Skip to content

Conversation

@julianladisch
Copy link
Contributor

https://folio-org.atlassian.net/browse/CIRC-2543

Purpose

Test dependency com.github.tomakehurst:wiremock-jre8:2.35.0 has this vulnerability:

Approach

Upgrade wiremock from 2.35.0 to 3.13.2

Learning

Switch to new artifact when mvnrepository.com shows "Artifact relocated": https://mvnrepository.com/artifact/com.github.tomakehurst/wiremock-jre8

com.github.tomakehurst:wiremock-jre8:2.35.0 has been released November 2022.

org.wiremock:wiremock:3.0.0 has been released August 2023.

The upgrade should have been made in 2023 or 2024.

https://folio-org.atlassian.net/browse/CIRC-2543

Purpose

Test dependency com.github.tomakehurst:wiremock-jre8:2.35.0 has this vulnerability:

* CVE-2023-41329 - GHSA-pmxq-pj47-j8j4 - Domain restrictions bypass via DNS Rebinding

Approach

Upgrade wiremock from 2.35.0 to 3.13.2
@sonarqubecloud
Copy link

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants