billmcchesney1 / pacbot

PacBot (Policy as Code Bot)
https://tmobile.github.io/pacbot/
Apache License 2.0
0 stars 0 forks source link

Update dependency org.quartz-scheduler:quartz to v2.3.2 - autoclosed #483

Closed mend-for-github-com[bot] closed 6 months ago

mend-for-github-com[bot] commented 8 months ago

This PR contains the following updates:

Package Type Update Change
org.quartz-scheduler:quartz (source) compile minor 2.2.3 -> 2.3.2

By merging this PR, the below issues will be automatically resolved and closed:

Severity CVSS Score CVE GitHub Issue
Critical 9.8 CVE-2019-13990 #128

Release Notes

quartz-scheduler/quartz (org.quartz-scheduler:quartz) ### [`v2.3.2`](https://togithub.com/quartz-scheduler/quartz/releases/tag/v2.3.2): Quartz 2.3.2 [Compare Source](https://togithub.com/quartz-scheduler/quartz/compare/v2.3.1...v2.3.2) This a bug fix release containing fixes for: - [#​508](https://togithub.com/quartz-scheduler/quartz/issues/508) : Error with H2 1.4.200 - [#​505](https://togithub.com/quartz-scheduler/quartz/issues/505) : CronTrigger.getTriggerBuilder() changes misfire instruction from "ignore misfire" to "smart" - [#​491](https://togithub.com/quartz-scheduler/quartz/issues/491) : StdJDBCDelegate.selectTriggerToAcquire may not respect maxCount - [#​490](https://togithub.com/quartz-scheduler/quartz/issues/490) : Return at most maxCount triggers - [#​482](https://togithub.com/quartz-scheduler/quartz/issues/482) : Update C3P0 version to 0.9.5.4 (CVE-2019-5427) - [#​474](https://togithub.com/quartz-scheduler/quartz/issues/474) : StdSchedulerFactory ConcurrentModificationException reading system properties - [#​467](https://togithub.com/quartz-scheduler/quartz/issues/467) : Security: XXE in initDocumentParser