The advisory for CVE-2024-36404
<https://github.com/geotools/geotools/security/advisories/GHSA-w3pj-wh35-fq8w>
is now published.

GeoTools 31.4 stable, GeoTools 30.4 maintenance, and GeoTools 29.6 (end of
life) have been patched.

I am not going to go over the details in email, please read the above link
(use of CVE system avoids risk of duplicated or outdated information).

Thanks to Steve for resolving this issue, and to Andrea for providing
patches for select prior releases.
--
Jody Garnett


On Jun 18, 2024 at 4:15:27 PM, Jody Garnett <jody.garn...@gmail.com> wrote:

> GeoTools 31.2 is now available from source forge and maven.
>
> This release is provided as an urgent update to address CVE-2024-36404. We
> will share details at the end of the month so you have some time to update
> your projects first.
>
> For more information and release notes see our blog post announcement GeoTools
> 31.2 Released
> <http://geotoolsnews.blogspot.com/2024/06/geotools-312-released.html>.
>
> Thanks to Jody (and GeoCat) for making this unscheduled release.
> --
> GeoTools Project Management Committee
>
_______________________________________________
GeoTools-GT2-Users mailing list
GeoTools-GT2-Users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/geotools-gt2-users

Reply via email to