Colm O hEigeartaigh created KARAF-7710:
------------------------------------------

             Summary: Fix CVE-2023-33201 in BouncyCastle
                 Key: KARAF-7710
                 URL: https://issues.apache.org/jira/browse/KARAF-7710
             Project: Karaf
          Issue Type: Bug
    Affects Versions: 4.4.3
            Reporter: Colm O hEigeartaigh
             Fix For: 4.4.4


Karaf 4.4.3 uses BouncyCastle 1.70 which is vulnerable to CVE-2023-33201.

I'll submit a PR to update to 1.75, which also involves changing the maven 
groupid from jdk15on to jdk18on.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to