[ https://issues.apache.org/jira/browse/KARAF-7710?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17745433#comment-17745433 ]
ASF subversion and git services commented on KARAF-7710: -------------------------------------------------------- Commit 7a5ff94052c6963a65b9cc5469d2f83f0cd5bf51 in karaf's branch refs/heads/main from Colm O hEigeartaigh [ https://gitbox.apache.org/repos/asf?p=karaf.git;h=7a5ff94052 ] KARAF-7710 - Update BouncyCastle to 1.75 > Fix CVE-2023-33201 in BouncyCastle > ---------------------------------- > > Key: KARAF-7710 > URL: https://issues.apache.org/jira/browse/KARAF-7710 > Project: Karaf > Issue Type: Bug > Affects Versions: 4.4.3 > Reporter: Colm O hEigeartaigh > Assignee: Jean-Baptiste Onofré > Priority: Major > > Karaf 4.4.3 uses BouncyCastle 1.70 which is vulnerable to CVE-2023-33201. > I'll submit a PR to update to 1.75, which also involves changing the maven > groupid from jdk15on to jdk18on. -- This message was sent by Atlassian Jira (v8.20.10#820010)