OxalisCommunity / Oxalis-AS4

PEPPOL AS4 pMode plugin for Oxalis
32 stars 26 forks source link

Upgrade CXF to latest version to get rid of CVE-2022-46364 and #197

Closed post-svejk closed 1 year ago

post-svejk commented 1 year ago

CVE-2022-46363

Also upgrade WSS4J to 2.4.1 which is supposed to work with CXF >= 3.4.*.

Pull Request Description

Fixes the above two vulnerabilities being reported against Oxalis-AS4 5.4.0 by snyk and Trivy. I have barely tested a snapshot of it with Oxalis 5.4.0 in a test environment at Digipost (both inbound and outbound processes), but haven't found any isses so far.

Not 100% sure yet if the upgrade breaks anything else.

Type of Pull Request

Type of Change

Pull Request Checklist:

post-svejk commented 1 year ago

@aaron-kumar : Can you have a look at this?