Skip to content

Update or replace dependencies to prevent vulnerabilities from transitive dependencies #11629

@gblaih

Description

@gblaih
<groupId>org.springframework.security</groupId>
<artifactId>spring-security-saml2-service-provider</artifactId>

<groupId>org.springframework.security</groupId>
<artifactId>spring-security-jwt</artifactId>

These dependencies are pulling in versions of other dependencies that contain vulnerabilities, such as those from org.apache.velocity and org.bouncycastle. See if these parent dependencies can be updated or replaced to prevent the need to force versions on or exclude their transitive dependencies.

Metadata

Metadata

Assignees

No one assigned

    Labels

    dependenciestriagetickets that need to be looked at before assigning to team members

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions