-
Component Upgrade
-
Resolution: Done-Errata
-
Major
-
None
-
False
-
None
-
False
-
-
-
-
-
-
-
Upgrade santuario(xmlsec) from 2.2.3 to 2.2.6 .
Release notes : https://issues.apache.org/jira/projects/SANTUARIO/versions/12353074
This upgrade includes the fix for CVE-2023-44483: Apache Santuario: Private Key disclosure in debug-log output
(https://nvd.nist.gov/vuln/detail/CVE-2023-44483)
Tag: https://github.com/apache/santuario-xml-security-java/releases/tag/xmlsec-2.2.6
Dif: https://github.com/apache/santuario-xml-security-java/compare/xmlsec-2.2.3...xmlsec-2.2.6
Hash: a6fdd4a275fdf6b50fb5c0a8edef5be7c6e7347c
- clones
-
JBEAP-25943 Upgrade santuario to 3.0.3
- Closed
- links to
-
RHSA-2023:120424 Red Hat JBoss Enterprise Application Platform 7.4.15 Security update
-
RHSA-2023:120425 Red Hat JBoss Enterprise Application Platform 7.4.15 Security update
-
RHSA-2023:120426 Red Hat JBoss Enterprise Application Platform 7.4.15Security update
-
RHSA-2023:120429 Red Hat JBoss Enterprise Application Platform 7.4.15 Security update