Skip to content

[BUG] SECURITY: hertzbeat uses bouncycastle jars that have multiple CVEs #3540

Open
@pjfanning

Description

@pjfanning

Is there an existing issue for this?

  • I have searched the existing issues

Current Behavior

BouncyCastle no longer ship jdk15on jars. Projects should use the jdk18on ones instead.
The jdk15on jars were for Java 1.5 users and fixes that have been made to the jdk18on jars (Java 1.8 compatible) have not been backported - including security fixes.

The last Hertzbeat RC had bcprov-jdk15on-1.69.jar

The classe names and packages are the same.

Expected Behavior

No response

Steps To Reproduce

No response

Environment

HertzBeat version(s):

Debug logs

No response

Anything else?

No response

Metadata

Metadata

Labels

bugSomething isn't workinggood first issueGood for newcomers

Type

No type

Projects

Status

To do

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions