Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade Bouncy Castle #272

Closed
barchetta opened this issue Jan 5, 2021 · 4 comments
Closed

Upgrade Bouncy Castle #272

barchetta opened this issue Jan 5, 2021 · 4 comments
Labels
SDK Issue pertains to the SDK itself and not specific to any service

Comments

@barchetta
Copy link
Member

<bouncycastle.version>1.60</bouncycastle.version>

See https://nvd.nist.gov/vuln/detail/CVE-2020-26939 and https://github.com/bcgit/bc-java/wiki/CVE-2020-26939

Recommends 1.61 or later.

@jodoglevy jodoglevy added the SDK Issue pertains to the SDK itself and not specific to any service label Jan 7, 2021
@omkar07
Copy link
Member

omkar07 commented Jan 11, 2021

hi @barchetta , thanks for filing this, we'll work on this issue soon.

@y-chandra
Copy link
Member

BouncyCastle has been updated to v1.64 in the latest version of the Java SDK (v1.30.1)

@ljnelson
Copy link
Member

@y-chandra Hello; I noticed that most of the OCI artifacts are now in Maven Central at version 1.30.1 but several are not. The latest version of oci-objectstorage artifacts is 1.30.0. Did the release not happen completely?

@ljnelson
Copy link
Member

Filed #280 to track.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
SDK Issue pertains to the SDK itself and not specific to any service
Projects
None yet
Development

No branches or pull requests

5 participants