SEAK, emulates a financial broker which allows you to buy and sell stocks at market price, place limit orders inside an order book and get the market data in real time.
CVE-2024-1597 and Security Advisory addressed. The vulnerability occurs only in non-default preferQueryMode=simple mode and only if a negative place holder -? is used. See the security advisory for details
security: SQL Injection via line comment generation, it is possible in SimpleQuery mode to generate a line comment by having a placeholder for a numeric with a -
such as -?. There must be second placeholder for a string immediately after. Setting the parameter to a -ve value creates a line comment.
This has been fixed in this version fixes CVE-2024-1597. Reported by Paul Gerste. See the security advisory for more details. This has been fixed in versions 42.7.2, 42.6.1 42.5.5, 42.4.4, 42.3.9, 42.2.28.jre7. See the security advisory for work arounds.
Changed
fix: Use simple query for isValid. Using Extended query sends two messages checkConnectionQuery was never ever set or used, removed [PR #3101](pgjdbc/pgjdbc#3101)
refactor: Document that encodePassword will zero out the password array, and remove driver's default encodePassword by @vlsi in [PR #3084](pgjdbc/pgjdbc#3084)
Bumps the gradle group with 11 updates:
2.22.1
2.23.1
2.22.1
2.23.1
2.22.1
2.23.1
2.22.1
2.23.1
2.22.1
2.23.1
2.16.1
2.16.2
2.16.1
2.16.2
2.16.1
2.16.2
42.7.1
42.7.2
6.2.1
6.2.2
1.19.4
1.19.7
1.19.4
1.19.7
1.19.4
1.19.7
1.19.4
1.19.7
1.19.4
1.19.7
1.19.4
1.19.7
1.19.4
1.19.7
Updates
org.apache.logging.log4j:log4j-api
from 2.22.1 to 2.23.1Updates
org.apache.logging.log4j:log4j-core
from 2.22.1 to 2.23.1Updates
org.apache.logging.log4j:log4j-slf4j2-impl
from 2.22.1 to 2.23.1Updates
org.apache.logging.log4j:log4j-core
from 2.22.1 to 2.23.1Updates
org.apache.logging.log4j:log4j-slf4j2-impl
from 2.22.1 to 2.23.1Updates
com.fasterxml.jackson.dataformat:jackson-dataformat-yaml
from 2.16.1 to 2.16.2Commits
d4977eb
[maven-release-plugin] prepare release jackson-dataformats-text-2.16.2cd23e6c
Prepare for 2.16.2 release55dd409
Merge branch '2.15' into 2.16ef3e7ae
Back to snapshot dep65cc7ec
[maven-release-plugin] prepare for next development iterationa133fd9
[maven-release-plugin] prepare release jackson-dataformats-text-2.15.4d543cd0
Prepare for 2.15.4 release8a573e5
Back to snapshot dep201a86e
[maven-release-plugin] prepare for next development iterationUpdates
com.fasterxml.jackson.core:jackson-databind
from 2.16.1 to 2.16.2Commits
Updates
com.fasterxml.jackson.core:jackson-databind
from 2.16.1 to 2.16.2Commits
Updates
org.postgresql:postgresql
from 42.7.1 to 42.7.2Release notes
Sourced from org.postgresql:postgresql's releases.
Changelog
Sourced from org.postgresql:postgresql's changelog.
Commits
06abfb7
Merge pull request from GHSA-24rp-q3w6-vc5693b0fcb
Merge pull request from GHSA-24rp-q3w6-vc56a408946
Revert "WIP speed up getDate (#3108)" (#3125)f5d6e3f
WIP speed up getDate (#3108)4e6a501
chore(deps): update release-drafter/release-drafter action to v60b90367
chore(deps): update dependency gradle to v8.64075f70
chore(deps): update oracle-actions/setup-java action to v1.3.38de5beb
fix(deps): update junit5 monorepo to v5.10.26f741dd
fix(deps): update dependency checkstyle to v10.13.007e0535
fix(deps): update dependency com.github.spotbugs:com.github.spotbugs.gradle.p...Updates
org.springframework.security:spring-security-crypto
from 6.2.1 to 6.2.2Release notes
Sourced from org.springframework.security:spring-security-crypto's releases.
... (truncated)
Commits
2cc6cbd
Release 6.2.215306c1
Merge branch '6.1.x' into 6.2.x750cb30
Add AuthenticationTrustResolver.isAuthenticated94f885c
Merge branch '6.1.x' into 6.2.x3093908
Merge branch '5.8.x' into 6.1.x6230806
Change branch pattern60057a3
Bump org.springframework.data:spring-data-bom from 2023.1.2 to 2023.1.35e7d6f8
Merge branch '6.1.x' into 6.2.xac87a1a
Merge branch '5.8.x' into 6.1.x2159f3a
Fix branch patternUpdates
org.testcontainers:junit-jupiter
from 1.19.4 to 1.19.7Release notes
Sourced from org.testcontainers:junit-jupiter's releases.
... (truncated)
Commits
4b5b34a
Enable lazy certificates for Elasticsearch (#7991)1846805
Improve Ollama docs (#8417)198b7fa
Fix openfga doc93ca7cd
Add Ollama module (#8369)33c904e
Update docker-java version to 3.3.6 (#8410)f23c1ec
Add oceanbase module (#7502)af5863c
Fix wrong permission setup for HiveMQ container (#8399)8bec80c
Update check list in settingsbfb837b
Add pgvector/pgvector as a compatible image (#7898) (#8401)e9902d5
openfga.md: fix typo in docker hub link (#8400)Updates
org.testcontainers:postgresql
from 1.19.4 to 1.19.7Release notes
Sourced from org.testcontainers:postgresql's releases.
... (truncated)
Commits
4b5b34a
Enable lazy certificates for Elasticsearch (#7991)1846805
Improve Ollama docs (#8417)198b7fa
Fix openfga doc93ca7cd
Add Ollama module (#8369)33c904e
Update docker-java version to 3.3.6 (#8410)f23c1ec
Add oceanbase module (#7502)af5863c
Fix wrong permission setup for HiveMQ container (#8399)8bec80c
Update check list in settingsbfb837b
Add pgvector/pgvector as a compatible image (#7898) (#8401)e9902d5
openfga.md: fix typo in docker hub link (#8400)Updates
org.testcontainers:kafka
from 1.19.4 to 1.19.7Release notes
Sourced from org.testcontainers:kafka's releases.
... (truncated)
Commits
4b5b34a
Enable lazy certificates for Elasticsearch (#7991)1846805
Improve Ollama docs (#8417)198b7fa
Fix openfga doc93ca7cd
Add Ollama module (#8369)33c904e
Update docker-java version to 3.3.6 (#8410)f23c1ec
Add oceanbase module (#7502)af5863c
Fix wrong permission setup for HiveMQ container (#8399)8bec80c
Update check list in settingsbfb837b
Add pgvector/pgvector as a compatible image (#7898) (#8401)e9902d5
openfga.md: fix typo in docker hub link (#8400)Updates
org.testcontainers:testcontainers
from 1.19.4 to 1.19.7Release notes
Sourced from org.testcontainers:testcontainers's releases.
... (truncated)
Commits
4b5b34a
Enable lazy certificates for Elasticsearch (#7991)1846805
Improve Ollama docs (#8417)198b7fa
Fix openfga doc93ca7cd
Add Ollama module (#8369)33c904e
Update docker-java version to 3.3.6 (#8410)f23c1ec
Add oceanbase module (#7502)af5863c
Fix wrong permission setup for HiveMQ container (#8399)8bec80c
Update check list in settingsbfb837b
Add pgvector/pgvector as a compatible image (#7898) (#8401)e9902d5
openfga.md: fix typo in docker hub link (#8400)Updates
org.testcontainers:postgresql
from 1.19.4 to 1.19.7Release notes
Sourced from org.testcontainers:postgresql's releases.
... (truncated)
Commits
4b5b34a
Enable lazy certificates for Elasticsearch (#7991)1846805
Improve Ollama docs (#8417)198b7fa
Fix openfga doc93ca7cd
Add Ollama module (#8369)33c904e
Update docker-java version to 3.3.6 (#8410)f23c1ec
Add oceanbase module (#7502)af5863c
Fix wrong permission setup for HiveMQ container (#8399)8bec80c
Update check list in settingsbfb837b
Add pgvector/pgvector as a compatible image (#7898) (#8401)e9902d5
openfga.md: fix typo in docker hub link (#8400)Updates
org.testcontainers:kafka
from 1.19.4 to 1.19.7Release notes
Sourced from org.testcontainers:kafka's releases.
... (truncated)
Commits
4b5b34a
Enable lazy certificates for Elasticsearch (#7991)1846805
Improve Ollama docs (#8417)198b7fa
Fix openfga doc93ca7cd
Add Ollama module (#8369)33c904e
Update docker-java version to 3.3.6 (#8410)f23c1ec
Add oceanbase module (#7502)af5863c
Fix wrong permission setup for HiveMQ container (#8399)8bec80c
Update check list in settingsbfb837b
Add pgvector/pgvector as a compatible image (#7898) (#8401)e9902d5
openfga.md: fix typo in docker hub link (#8400)Updates
org.testcontainers:testcontainers
from 1.19.4 to 1.19.7Release notes
Sourced from org.testcontainers:testcontainers's releases.