Skip to content

fix: bump commons-compress from 1.25.0 to 1.26.0 to fix CVE-2024-25710 and CVE-2024-26308#6492

Merged
jeremylong merged 1 commit intodependency-check:mainfrom
jmonsma:fix/cve-2024-25710
Mar 12, 2024
Merged

fix: bump commons-compress from 1.25.0 to 1.26.0 to fix CVE-2024-25710 and CVE-2024-26308#6492
jeremylong merged 1 commit intodependency-check:mainfrom
jmonsma:fix/cve-2024-25710

Conversation

@jmonsma
Copy link
Copy Markdown
Contributor

@jmonsma jmonsma commented Feb 28, 2024

Fixes Issue

CVE-2024-25710
CVE-2024-26308

Description of Change

Bumped package version from 1.25.0 to 1.26.0 that fixes the CVE's

Have test cases been added to cover the new functionality?

No

@jmonsma jmonsma changed the title Bump commons-compress from 1.25.0 to 1.26.0 to fix CVE-2024-25710 and CVE-2024-26308 fixL Bump commons-compress from 1.25.0 to 1.26.0 to fix CVE-2024-25710 and CVE-2024-26308 Feb 28, 2024
@jmonsma jmonsma changed the title fixL Bump commons-compress from 1.25.0 to 1.26.0 to fix CVE-2024-25710 and CVE-2024-26308 fix: bump commons-compress from 1.25.0 to 1.26.0 to fix CVE-2024-25710 and CVE-2024-26308 Feb 28, 2024
@aikebah aikebah added this to the 9.0.10 milestone Mar 10, 2024
@jeremylong jeremylong merged commit 04aff68 into dependency-check:main Mar 12, 2024
@github-actions github-actions Bot locked as resolved and limited conversation to collaborators Dec 9, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants