Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
EDGOAIPMH-108: RMB 35.1.1, Vert.x 4.4.6 fixing Netty/Jackson DoS (#106)
Upgrade RMB from the Orchid version 35.0.6 to the Poppy version 35.1.1. Upgrade Vert.x from 4.3.8 to 4.4.6. Versions 4.3.x have been out of support since March 2023. Upgrade log4j from 2.17.2 to 2.20.0. edge-common comes with 2.20.0 and we should not downgrade the version. The Vert.x upgrade indirectly upgrades Netty from 4.1.87.Final to 4.1.100.Final fixing Denial of Service (DoS): https://nvd.nist.gov/vuln/detail/CVE-2023-44487 , https://nvd.nist.gov/vuln/detail/CVE-2023-34462 The RMB upgrade indirectly upgrades Jackson from 2.14.0 to 2.15.0 fixing Number Parse DoS: FasterXML/jackson-core#827 (PRISMA-2023-0067) (cherry picked from commit 4341dd8)
- Loading branch information