Update transitive dependency protobuf-java to fix CVE-2022-3171
This commit is contained in:
parent
ccaa50ad67
commit
ee8ecfc74b
11
pom.xml
11
pom.xml
@ -124,8 +124,19 @@
|
||||
<dependency>
|
||||
<groupId>mysql</groupId>
|
||||
<artifactId>mysql-connector-java</artifactId>
|
||||
<!-- when updating check which version of protobuf-java it depends on -->
|
||||
<!-- and upgrade to the appropriate patched version -->
|
||||
<version>8.0.30</version>
|
||||
</dependency>
|
||||
<dependency>
|
||||
<!-- transitive dependency of mysql-connector-java -->
|
||||
<!-- it depends on version 3.19.4 which has a security vulnerability -->
|
||||
<!-- when updating mysql-connector-java check which version it depends on -->
|
||||
<!-- and upgrade to the appropriate patched version of protobuf-java -->
|
||||
<groupId>com.google.protobuf</groupId>
|
||||
<artifactId>protobuf-java</artifactId>
|
||||
<version>3.19.6</version>
|
||||
</dependency>
|
||||
|
||||
<!--QueryDSL-->
|
||||
<dependency>
|
||||
|
Loading…
x
Reference in New Issue
Block a user