[ 
https://issues.apache.org/jira/browse/KARAF-7710?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Jean-Baptiste Onofré resolved KARAF-7710.
-----------------------------------------
    Fix Version/s: 4.4.4
                   4.3.10
       Resolution: Fixed

> Fix CVE-2023-33201 in BouncyCastle
> ----------------------------------
>
>                 Key: KARAF-7710
>                 URL: https://issues.apache.org/jira/browse/KARAF-7710
>             Project: Karaf
>          Issue Type: Bug
>    Affects Versions: 4.4.3
>            Reporter: Colm O hEigeartaigh
>            Assignee: Jean-Baptiste Onofré
>            Priority: Major
>             Fix For: 4.4.4, 4.3.10
>
>
> Karaf 4.4.3 uses BouncyCastle 1.70 which is vulnerable to CVE-2023-33201.
> I'll submit a PR to update to 1.75, which also involves changing the maven 
> groupid from jdk15on to jdk18on.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to