[
https://issues.apache.org/jira/browse/KARAF-7710?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17745434#comment-17745434
]
ASF subversion and git services commented on KARAF-7710:
--------------------------------------------------------
Commit 997a909f5fc3b7d620f9f866ae20beb64316614e in karaf's branch
refs/heads/main from JB Onofré
[ https://gitbox.apache.org/repos/asf?p=karaf.git;h=997a909f5f ]
Merge pull request #1726 from coheigea/coheigea/KARAF-7710
KARAF-7710 - Update BouncyCastle to 1.75
> Fix CVE-2023-33201 in BouncyCastle
> ----------------------------------
>
> Key: KARAF-7710
> URL: https://issues.apache.org/jira/browse/KARAF-7710
> Project: Karaf
> Issue Type: Bug
> Affects Versions: 4.4.3
> Reporter: Colm O hEigeartaigh
> Assignee: Jean-Baptiste Onofré
> Priority: Major
>
> Karaf 4.4.3 uses BouncyCastle 1.70 which is vulnerable to CVE-2023-33201.
> I'll submit a PR to update to 1.75, which also involves changing the maven
> groupid from jdk15on to jdk18on.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)