Uploaded image for project: 'Nuxeo Platform'
  1. Nuxeo Platform
  2. NXP-32150

Upgrade guava and auto-value

    XMLWordPrintable

    Details

    • Type: Bug
    • Status: Resolved
    • Priority: Major
    • Resolution: Fixed
    • Affects Version/s: 2021.0
    • Fix Version/s: 2023.4, 2021.46
    • Component/s: Security
    • Backlog priority:
      900
    • Upgrade notes:
      Hide

      The following dependency:

      <dependency>
        <groupId>com.google.guava</groupId>
        <artifactId>guava</artifactId>
      </dependency>
      

      has been upgraded:

      • In 2021: from 32.0.0-jre to 32.0.1-jre
      • In 2023: from 31.1-jre to 32.0.1-jre
      Show
      The following dependency: <dependency> <groupId>com.google.guava</groupId> <artifactId>guava</artifactId> </dependency> has been upgraded: In 2021: from 32.0.0-jre to 32.0.1-jre In 2023: from 31.1-jre to 32.0.1-jre
    • Sprint:
      nxplatform #101
    • Story Points:
      2

      Description

      Because of CVE-2023-2976 an upgrade of guava and auto-value is required

      • guava >= 32.0.1-jre
      • auto-value >= 1.10.2 (this version correspond to 32.0.1-jre)

        Attachments

          Issue Links

            Activity

              People

              • Votes:
                0 Vote for this issue
                Watchers:
                4 Start watching this issue

                Dates

                • Created:
                  Updated:
                  Resolved: