Skip to content

Pacthes CVE-2025-48924 and CVE-2025-22227#311

Merged
petruki merged 1 commit intomasterfrom
staging
Jul 19, 2025
Merged

Pacthes CVE-2025-48924 and CVE-2025-22227#311
petruki merged 1 commit intomasterfrom
staging

Conversation

@petruki
Copy link
Member

@petruki petruki commented Jul 19, 2025

This pull request updates dependencies in the pom.xml file to address security vulnerabilities and ensure compatibility. The most important changes include upgrading the switcher-client.version, re-adding and updating commons-lang3.version with a security patch, and adding dependencies for reactor-netty to address vulnerabilities.

Dependency updates:

  • pom.xml: Upgraded switcher-client.version from 2.3.1 to 2.3.2 to ensure compatibility with the latest features or fixes.

Security patches:

  • pom.xml: Re-added commons-lang3.version with an updated version (3.18.0) to patch a high-severity uncontrolled recursion vulnerability.
  • pom.xml: Added dependencies for reactor-netty-http and reactor-netty-core (version 1.2.8) to patch a low-severity vulnerability.

@petruki petruki added this to the v2.0.1 milestone Jul 19, 2025
@petruki petruki self-assigned this Jul 19, 2025
@petruki petruki added patch Update internal dependencies security Vulnerability found labels Jul 19, 2025
@sonarqubecloud
Copy link

@petruki petruki merged commit ffc2331 into master Jul 19, 2025
5 checks passed
@petruki petruki deleted the staging branch July 19, 2025 02:06
petruki added a commit that referenced this pull request Jul 19, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

patch Update internal dependencies security Vulnerability found

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant