Skip to content

[Snyk] Security upgrade org.apache.santuario:xmlsec from 1.5.8 to 2.2.6#73

Closed
iText-CI wants to merge 4437 commits intodevelopfrom
snyk-fix-101cf6c07a53d555eb705e7cc0cb5ae1
Closed

[Snyk] Security upgrade org.apache.santuario:xmlsec from 1.5.8 to 2.2.6#73
iText-CI wants to merge 4437 commits intodevelopfrom
snyk-fix-101cf6c07a53d555eb705e7cc0cb5ae1

Conversation

@iText-CI
Copy link
Contributor

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `maven` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • itext/pom.xml

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Upgrade Breaking Change Exploit Maturity
high severity 661/1000
Why? Recently disclosed, Has a fix available, CVSS 7.5
Insertion of Sensitive Information into Log File
SNYK-JAVA-ORGAPACHESANTUARIO-6017551
org.apache.santuario:xmlsec:
1.5.8 -> 2.2.6
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Insertion of Sensitive Information into Log File

amedee and others added 30 commits February 3, 2016 15:18
Pass mvn command to ssh directly.
Don't forget to add `-w` to `git diff` and `git blame` to get a correct change history.
* Explicitly set Java version to 1.5
* Put blocks in the recommended ordering according to POM Code Convention:
  https://maven.apache.org/developers/conventions/code.html
* Change mailing list to StackOverflow
* Change SCM to Git

Resolves QA-62
…ame role so if the role is different it is not overwritten.
This allows com.itextpdf:itextpdf to be replaced by com.itextpdf:itextg on Android / GAE.
The default value for `parent.relativePath` is `../pom.xml` and that default value gets injected in the effective pom, triggering the warning.
Add an empty `<relativePath>` to `<parent>` so that it resolves the parent pom from the repositories.
Snipx and others added 28 commits March 31, 2020 13:02
Merge branch 'release/5.5.13.2' into master
iText 5 is deprecated and we are not accepting PRs except security fixes

DEVSIX-4793
Merge branch 'release/5.5.13.3' into master
…able version of commons-imaging

Change commons-imaging dependency to version 1.0-alpha1 instead of 1.0-SNAPSHOT.

DEVSIX-6698
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Comments