From 98b698adc2271ca1d616474cabc3c8ba2081e4ca Mon Sep 17 00:00:00 2001 From: Jason Frame Date: Thu, 19 Oct 2023 16:01:36 +1000 Subject: [PATCH] Override the netty dependency to fix CVE-2023-44487 (#932) --- CHANGELOG.md | 5 +++++ gradle/owasp-suppression.xml | 12 ------------ gradle/versions.gradle | 10 ++++++++-- 3 files changed, 13 insertions(+), 14 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index f05127d74..2059899e3 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,10 @@ # Changelog +## Next version + +### Bugs fixed +- Update netty to fix CVE-2023-44487 + ## 23.9.1 ### Breaking Changes diff --git a/gradle/owasp-suppression.xml b/gradle/owasp-suppression.xml index 8139f5056..90bc4fa57 100644 --- a/gradle/owasp-suppression.xml +++ b/gradle/owasp-suppression.xml @@ -1,18 +1,6 @@ - - - ^pkg:maven/io\.netty/netty*@*.*$ - CVE-2023-4586 -