Xavier Fernandis created HBASE-30298:
----------------------------------------

             Summary: Bump Jruby to 9.4.15.0 to address multiple CVE's.
                 Key: HBASE-30298
                 URL: https://issues.apache.org/jira/browse/HBASE-30298
             Project: HBase
          Issue Type: Task
            Reporter: Xavier Fernandis
            Assignee: Xavier Fernandis


*There are some of the vulnerabilites fix in 9.4.15.0*
CVE-2025-14813
CVE-2026-41316
CVE-2026-5598
sonatype-2025-001911
CVE-2026-5588
CVE-2026-0636
CVE-2025-58767


Upgraded jruby 9.4.14.0 → 9.4.15.0 to remediate the BouncyCastle CVEs flagged 
in this finding: jruby-complete embeds BC as nested jars in its
  stdlib (1.79), which Maven dependency management cannot override, so the 
bundled copy was only upgradable via the jruby bump.
Post-upgrade jruby ships BC 1.84 — aligned with HBase's existing 1.84 — with 
joni (2.2.5) and jcodings (1.0.63) verified unchanged and compatible.


 



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to