Fulcrum Security Hibernate Module
"Georg Kallidis" <[email protected]>
| Newsgroups | gmane.comp.jakarta.turbine.devel |
|---|---|
| Message-ID | <OF06E73279.A7EA922E-ONC125876F.004E36E9-C125876F.004FCEFE@cedis.fu-berlin.de> |
Hi Turbine Dev community, before we are ready to come up with the "big" Turbine Core release 5.1 (any volunteers noticing it now ;-)!) we need to do a Fulcrum Security Component release, as it is a core dependency. But I still get vulnerability warnings for the hibernate module, if I run mvn org.owasp:dependency-check-maven:aggregate -DskipTests=true https://nvd.nist.gov/vuln/detail/CVE-2020-25638 https://nvd.nist.gov/vuln/detail/CVE-2019-14900 We have the following options: a) just wait until someone is prepared to fix it by upgrading (at least to hibernate 5.3.23 from 3.6.10). b) ignore it (suppress it) or c) disable/remove it ? Does anyone need this component to be up-to-date soon ? If no, IMO we should disable it for now -? Nevertheless a JIRA task-issue could be opened to do it later .. Best regards, Georg
smime.p7s
(application/x-pkcs7-signature, 11.1 KB) - not displayed