SimaTankSAAS / nifi-1.4.0

Apache License 2.0
0 stars 1 forks source link

Update dependency org.springframework.security:spring-security-core to v4.2.16.RELEASE - autoclosed #111

Closed mend-for-github-com[bot] closed 6 months ago

mend-for-github-com[bot] commented 8 months ago

This PR contains the following updates:

Package Type Update Change
org.springframework.security:spring-security-core (source) compile patch 4.2.13.RELEASE -> 4.2.16.RELEASE

By merging this PR, the issue #110 will be automatically resolved and closed:

Severity CVSS Score CVE
Medium Medium 6.5 CVE-2020-5408

Release Notes

spring-projects/spring-security (org.springframework.security:spring-security-core) ### [`v4.2.16.RELEASE`](https://togithub.com/spring-projects/spring-security/releases/tag/4.2.16.RELEASE) [Compare Source](https://togithub.com/spring-projects/spring-security/compare/4.2.15.RELEASE...4.2.16.RELEASE) #### :beetle: Bug Fixes - Fix Javadoc punctuation [#​8486](https://togithub.com/spring-projects/spring-security/issues/8486) - Add ROLE_INFRASTRUCTURE to infrastructure beans [#​8442](https://togithub.com/spring-projects/spring-security/issues/8442) - SEC-2664: ActiveDirectoryLdapAuthenticationProvider should wrap communication exceptions in InternalAuthenticationServiceException [#​8433](https://togithub.com/spring-projects/spring-security/issues/8433) - Fix example in javadoc of FilterChainProxy [#​8355](https://togithub.com/spring-projects/spring-security/issues/8355) ### [`v4.2.15.RELEASE`](https://togithub.com/spring-projects/spring-security/releases/tag/4.2.15.RELEASE) [Compare Source](https://togithub.com/spring-projects/spring-security/compare/4.2.14.RELEASE...4.2.15.RELEASE) #### :star: New Features - SwitchUserFilter vulnerable to CSRF [#​8226](https://togithub.com/spring-projects/spring-security/issues/8226) - Update Encryptors documentation for standard and stronger [#​8219](https://togithub.com/spring-projects/spring-security/issues/8219) - Typo 'properites' -> 'properties' in documentation [#​8102](https://togithub.com/spring-projects/spring-security/issues/8102) #### :beetle: Bug Fixes - HttpServletRequest.logout() not functioning [#​8244](https://togithub.com/spring-projects/spring-security/issues/8244) - Spring Security BOM 4.2.14.RELEASE is missing [#​7975](https://togithub.com/spring-projects/spring-security/issues/7975) #### :hammer: Dependency Upgrades - Update to jackson-databind:2.8.11.6 [#​8273](https://togithub.com/spring-projects/spring-security/issues/8273) - Update to appengine:1.9.79 [#​8272](https://togithub.com/spring-projects/spring-security/issues/8272) - Update to spring-io-plugin:0.0.8.RELEASE [#​8271](https://togithub.com/spring-projects/spring-security/issues/8271) - Update to nekohtml:1.9.22 [#​8270](https://togithub.com/spring-projects/spring-security/issues/8270) - Update to thymeleaf-layout-dialect:2.0.5 [#​8269](https://togithub.com/spring-projects/spring-security/issues/8269) - Update to httpclient:4.2.6 [#​8268](https://togithub.com/spring-projects/spring-security/issues/8268) - Update to taglibs-standard-jstlel:1.2.5 [#​8267](https://togithub.com/spring-projects/spring-security/issues/8267) - Update to Jetty 8.1.22.v20160922 [#​8266](https://togithub.com/spring-projects/spring-security/issues/8266) - Update to Tomcat 7.0.103 [#​8265](https://togithub.com/spring-projects/spring-security/issues/8265) - Update to asciidoctor-gradle-plugin:1.5.7 [#​8264](https://togithub.com/spring-projects/spring-security/issues/8264) - Update to Groovy 2.4.19 [#​8263](https://togithub.com/spring-projects/spring-security/issues/8263) - Update to spring-boot-gradle-plugin:1.5.22.RELEASE [#​8262](https://togithub.com/spring-projects/spring-security/issues/8262) ### [`v4.2.14.RELEASE`](https://togithub.com/spring-projects/spring-security/releases/tag/4.2.14.RELEASE) [Compare Source](https://togithub.com/spring-projects/spring-security/compare/4.2.13.RELEASE...4.2.14.RELEASE) #### :star: New Features - Build 4.2.x on Jenkins [#​7940](https://togithub.com/spring-projects/spring-security/issues/7940) - Remove Dependency on Bamboo [#​7939](https://togithub.com/spring-projects/spring-security/issues/7939) #### :hammer: Dependency Upgrades - Update to Thymeleaf 3.0.11.RELEASE [#​7948](https://togithub.com/spring-projects/spring-security/issues/7948) - Update to Spring Boot 1.5.22.RELEASE [#​7947](https://togithub.com/spring-projects/spring-security/issues/7947) - Update to Spring Session 1.3.5.RELEASE [#​7946](https://togithub.com/spring-projects/spring-security/issues/7946) - Update to Spring Data Redis 1.8.23.RELEASE [#​7945](https://togithub.com/spring-projects/spring-security/issues/7945) - Update to Spring Data JPA 1.11.23.RELEASE [#​7944](https://togithub.com/spring-projects/spring-security/issues/7944) - Update to Spring Data Commons 1.13.23.RELEASE [#​7943](https://togithub.com/spring-projects/spring-security/issues/7943) - Update to CGLIB 3.2.12 [#​7942](https://togithub.com/spring-projects/spring-security/issues/7942) - Update to Spring Framework 4.3.26.RELEASE [#​7941](https://togithub.com/spring-projects/spring-security/issues/7941)