Uploaded image for project: 'JBoss Enterprise Application Platform'
  1. JBoss Enterprise Application Platform
  2. JBEAP-25944

Upgrade santuario to 2.2.6 to include the CVE-2023-44483 fix

    XMLWordPrintable

Details

    Description

      Upgrade santuario(xmlsec) from 2.2.3 to 2.2.6 . 

      Release notes : https://issues.apache.org/jira/projects/SANTUARIO/versions/12353074

      This upgrade includes the fix for  CVE-2023-44483: Apache Santuario: Private Key disclosure in debug-log output

      (https://nvd.nist.gov/vuln/detail/CVE-2023-44483)

       

      Tag: https://github.com/apache/santuario-xml-security-java/releases/tag/xmlsec-2.2.6
      Dif: https://github.com/apache/santuario-xml-security-java/compare/xmlsec-2.2.3...xmlsec-2.2.6
      Hash: a6fdd4a275fdf6b50fb5c0a8edef5be7c6e7347c

      Attachments

        Issue Links

          Activity

            People

              rhn-engineering-ema Jim Ma
              rhn-engineering-ema Jim Ma
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: