Skip to content

Commit

Permalink
HADOOP-17563. Upgrade BouncyCastle to 1.68 (apache#3980)
Browse files Browse the repository at this point in the history
Addresses CVE-2020-15522 and CVE-2020-26939.

This can break builds with older maven shade plugins or
other code using asm.jar which is not aware of recent java bytecodes
and/or multirelease JARs.

Contributed by PJ Fanning

Change-Id: Iea08fbd03acd2ce5b61164b1f9c92a0e61207a6b
  • Loading branch information
pjfanning authored and steveloughran committed Oct 14, 2022
1 parent 08760fc commit 98c7a56
Show file tree
Hide file tree
Showing 2 changed files with 3 additions and 3 deletions.
4 changes: 2 additions & 2 deletions LICENSE-binary
Original file line number Diff line number Diff line change
Expand Up @@ -451,8 +451,8 @@ com.microsoft.azure:azure-cosmosdb-gateway:2.4.5
com.microsoft.azure:azure-data-lake-store-sdk:2.3.9
com.microsoft.azure:azure-keyvault-core:1.0.0
com.microsoft.sqlserver:mssql-jdbc:6.2.1.jre7
org.bouncycastle:bcpkix-jdk15on:1.60
org.bouncycastle:bcprov-jdk15on:1.60
org.bouncycastle:bcpkix-jdk15on:1.68
org.bouncycastle:bcprov-jdk15on:1.68
org.checkerframework:checker-qual:2.5.2
org.checkerframework:checker-qual:3.8.0
org.codehaus.mojo:animal-sniffer-annotations:1.17
Expand Down
2 changes: 1 addition & 1 deletion hadoop-project/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -106,7 +106,7 @@
<guice.version>4.0</guice.version>
<joda-time.version>2.9.9</joda-time.version>

<bouncycastle.version>1.60</bouncycastle.version>
<bouncycastle.version>1.68</bouncycastle.version>

<!-- Required for testing LDAP integration -->
<apacheds.version>2.0.0-M21</apacheds.version>
Expand Down

0 comments on commit 98c7a56

Please sign in to comment.