Closed kebeda closed 1 year ago
@thinkingserious @twilio-dx can someone look into this?
Please mitigate this vulnerability by updating Bouncy Castle @childish-sambino @twilio-dx @twilio-taylorferguson @twilio-ci
Latest is now 1.76 which fixes an additional vulnerability.
Any update on this?
I'm also interested in updates on this, would love to resolve this CVE in my project. Thanks in advance!
Please mitigate this vulnerability by updating Bouncy Castle @sendgrid-argo-cd @sendgrid-ci @sendgrid-github-readonly @sendgrid-jira @SendGridDX
Might make sense for maintainers to create a fresh pr for fix
Th last commit on main branch was Jan 3. Why the need for a new PR?
@shrutiburman this was merged with 1.75 instead of 1.76, the latest bouncycastle version -- will there be a separate pull request to update the latest?
@shrutiburman opened a PR here https://github.com/sendgrid/sendgrid-java/pull/744
Oh, thanks @mrdziuban for the PR. I'll merge that once all runs are passing.
Done.
This mitigates CVE-2023-33201.
ref. https://github.com/bcgit/bc-java/wiki/CVE-2023-33201