Skip to content
This repository was archived by the owner on Feb 5, 2024. It is now read-only.

Upgrade xalan 2.7.3 that contains bcel 6.7.0#17

Merged
edbratt merged 1 commit into
javaee:masterfrom
jbescos:xalan2.7.3
Sep 11, 2023
Merged

Upgrade xalan 2.7.3 that contains bcel 6.7.0#17
edbratt merged 1 commit into
javaee:masterfrom
jbescos:xalan2.7.3

Conversation

@jbescos
Copy link
Copy Markdown
Contributor

@jbescos jbescos commented Sep 11, 2023

Apache Commons BCEL 6.6.0 addressed CVE-2022-42920. CVE-2022-42920 is a publicly reported vulnerability. The CVSS v3.1 score in NVD is 9.8. Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics.

Current version of JSTL-API version, that depends on xalan 2.7.2, contains a shaded BCEL 6.6.0.

Signed-off-by: Jorge Bescos Gascon <jorge.bescos.gascon@oracle.com>
Copy link
Copy Markdown
Member

@edbratt edbratt left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM
Thank you!

@edbratt edbratt merged commit b3f3d7d into javaee:master Sep 11, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants