|
94 | 94 | <artifactId>commons-lang3</artifactId> |
95 | 95 | <version>3.19.0</version> |
96 | 96 | </dependency> |
| 97 | + <!-- Fix for CVE-2025-24970, CVE-2025-58056, CVE-2025-58057 and CVE-2025-55163: Override Netty version from transitive dependencies --> |
| 98 | + <dependency> |
| 99 | + <groupId>io.netty</groupId> |
| 100 | + <artifactId>netty-bom</artifactId> |
| 101 | + <version>4.2.5.Final</version> |
| 102 | + <type>pom</type> |
| 103 | + <scope>import</scope> |
| 104 | + </dependency> |
| 105 | + <!-- Fix for CVE-2025-27820: Override httpclient5 version from AWS SDK transitive dependencies --> |
| 106 | + <dependency> |
| 107 | + <groupId>org.apache.httpcomponents.client5</groupId> |
| 108 | + <artifactId>httpclient5</artifactId> |
| 109 | + <version>5.4.3</version> |
| 110 | + </dependency> |
| 111 | + <!-- Fix for CVE-2024-57699: Override json-smart version from transitive dependencies --> |
| 112 | + <dependency> |
| 113 | + <groupId>net.minidev</groupId> |
| 114 | + <artifactId>json-smart</artifactId> |
| 115 | + <version>2.5.2</version> |
| 116 | + </dependency> |
| 117 | + <!-- Fix for CVE-2020-15250: Override junit version from transitive dependencies --> |
| 118 | + <dependency> |
| 119 | + <groupId>junit</groupId> |
| 120 | + <artifactId>junit</artifactId> |
| 121 | + <version>${junit.version}</version> |
| 122 | + </dependency> |
97 | 123 | </dependencies> |
98 | 124 | </dependencyManagement> |
99 | 125 | <organization> |
|
337 | 363 | <!-- 4. commons-text declares commons-lang3 3.13.0 (< 3.18.0) --> |
338 | 364 | <exclude>META-INF/maven/org.apache.commons/commons-text/pom.xml</exclude> |
339 | 365 | <exclude>META-INF/maven/org.apache.commons/commons-text/pom.properties</exclude> |
| 366 | + <!-- 5. Fix for CVE-2020-15250: json-simple declares old junit --> |
| 367 | + <exclude>META-INF/maven/com.googlecode.json-simple/json-simple/pom.xml</exclude> |
| 368 | + <exclude>META-INF/maven/com.googlecode.json-simple/json-simple/pom.properties</exclude> |
| 369 | + <!-- 6. Exclude old junit POM metadata directly --> |
| 370 | + <exclude>META-INF/maven/junit/junit/pom.xml</exclude> |
| 371 | + <exclude>META-INF/maven/junit/junit/pom.properties</exclude> |
340 | 372 | </excludes> |
341 | 373 | </filter> |
342 | 374 | </filters> |
|
0 commit comments