Skip to content
This repository was archived by the owner on Feb 5, 2024. It is now read-only.

Upgrade xalan 2.7.3 that contains bcel 6.7.0 #17

Merged
merged 1 commit into from
Sep 11, 2023

Conversation

jbescos
Copy link
Contributor

@jbescos jbescos commented Sep 11, 2023

Apache Commons BCEL 6.6.0 addressed CVE-2022-42920. CVE-2022-42920 is a publicly reported vulnerability. The CVSS v3.1 score in NVD is 9.8. Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics.

Current version of JSTL-API version, that depends on xalan 2.7.2, contains a shaded BCEL 6.6.0.

Copy link
Member

@edbratt edbratt left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM
Thank you!

@edbratt edbratt merged commit b3f3d7d into javaee:master Sep 11, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants