Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependencies to fix critical and high severity vulnerabilities #827

Open
ic2hrmk opened this issue Jan 5, 2023 · 1 comment · May be fixed by #1001
Open

Update dependencies to fix critical and high severity vulnerabilities #827

ic2hrmk opened this issue Jan 5, 2023 · 1 comment · May be fixed by #1001
Labels

Comments

@ic2hrmk
Copy link

ic2hrmk commented Jan 5, 2023

Current Behavior

Hi,

There are dependencies imported with High to Critical severity vulnerabilities. Wouldn't you mind bumping its versions?

Expected Behavior

Recommended versions:

  • org.yaml_sankeyaml@1.31
  • com.fasterxml.jackson.core_jackson-databind@2.14.0

Steps To Reproduce

No response

Environment

  • keycloak-config-cli Version: v5.5.0
  • Java Version: 11

Anything else?

No response

@ic2hrmk ic2hrmk added the bug label Jan 5, 2023
@FraPazGal
Copy link

To give a bit more context on this, CVE-2022-1471 actually requires org.yaml_sankeyaml@2.

A couple of new vulnerabilities are also shown when running Trivy on it, CVE-2023-20861 and CVE-2023-20863. These 2 are related to Spring core and should be fixed updating it to 5.3.27.

Could you give more information on whether these vulnerabilities affect the CLI and if there is a plan to address them?

@jonasvoelcker jonasvoelcker linked a pull request Mar 14, 2024 that will close this issue
1 task
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants