Fulcrum Security Hibernate Module

"Georg Kallidis" <[email protected]>
Newsgroups gmane.comp.jakarta.turbine.devel
Message-ID <OF06E73279.A7EA922E-ONC125876F.004E36E9-C125876F.004FCEFE@cedis.fu-berlin.de>
Hi Turbine Dev community,

before we are ready to come up with the "big" Turbine Core release 5.1 
(any volunteers noticing it now ;-)!) 
we need to do a Fulcrum Security Component release, as it is a core 
dependency.

But I still get vulnerability warnings for the hibernate module, if I run

mvn org.owasp:dependency-check-maven:aggregate -DskipTests=true

https://nvd.nist.gov/vuln/detail/CVE-2020-25638
https://nvd.nist.gov/vuln/detail/CVE-2019-14900

We have the following options: 

a) just wait until someone is prepared to fix it by upgrading (at least to 
hibernate 5.3.23 from 3.6.10).
b) ignore it (suppress it) or
c) disable/remove it ?

Does anyone need this component to be up-to-date soon ? If no, IMO we 
should disable it for now -? 

Nevertheless a JIRA task-issue could be opened to do it later ..


Best regards, Georg
smime.p7s (application/x-pkcs7-signature, 11.1 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.