Browse Source

security: upgrade nimbus-jose-jwt to 9.37.4 (patched version)

- Update from 9.37.2 to 9.37.4 to address CVE
- 9.37.2 is vulnerable, 9.37.4 is the patched version for 9.x line
- Verified with mvn dependency:tree that override is applied
pull/7526/head
chrislu 7 days ago
parent
commit
9078ea64f1
  1. 2
      test/java/spark/pom.xml

2
test/java/spark/pom.xml

@ -167,7 +167,7 @@
<dependency> <dependency>
<groupId>com.nimbusds</groupId> <groupId>com.nimbusds</groupId>
<artifactId>nimbus-jose-jwt</artifactId> <artifactId>nimbus-jose-jwt</artifactId>
<version>9.37.2</version>
<version>9.37.4</version>
</dependency> </dependency>
<!-- Snappy Java - Fix CVEs --> <!-- Snappy Java - Fix CVEs -->

Loading…
Cancel
Save