Skip to content

Commit 6a01168

Browse files
committed
Add constraints on spring-boot-starter-undertow dependency to use xnio-api 3.8.16.Final instead of 3.8.8.Final (CVE-2023-5685)
1 parent d0d340a commit 6a01168

File tree

1 file changed

+3
-1
lines changed

1 file changed

+3
-1
lines changed

build.gradle.kts

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -278,7 +278,9 @@ subprojects {
278278
implementation("org.springframework.boot:spring-boot-starter-web") {
279279
exclude(group = "org.springframework.boot", module = "spring-boot-starter-tomcat")
280280
}
281-
implementation("org.springframework.boot:spring-boot-starter-undertow")
281+
implementation("org.springframework.boot:spring-boot-starter-undertow") {
282+
constraints { implementation("org.jboss.xnio:xnio-api:3.8.16.Final") }
283+
}
282284
implementation("com.fasterxml.jackson.module:jackson-module-kotlin")
283285
// https://mvnrepository.com/artifact/jakarta.validation/jakarta.validation-api
284286
implementation("jakarta.validation:jakarta.validation-api:$apiValidationVersion")

0 commit comments

Comments
 (0)