sshj icon indicating copy to clipboard operation
sshj copied to clipboard

0.38.0 has high bouncycastle security vulnerability

Open BernhardLenz opened this issue 1 year ago • 1 comments

According to mvnrepository, sshj version 0.38.0 uses org.bouncycastle:bcprov-jdk18on:jar:1.75.

However bouncycastle has a high security vulnerability: https://security.snyk.io/vuln/SNYK-JAVA-ORGBOUNCYCASTLE-6612984

Can you please release 0.39.0 with bounceycastle 1.78.1?

BernhardLenz avatar Apr 30 '24 21:04 BernhardLenz

I submitted pull request #945 to upgrade Bouncy Castle to 1.78.1. For projects depending on SSHJ, it is possible to override the transitive dependency version of bcprov-jdk18on.

exceptionfactory avatar May 15 '24 21:05 exceptionfactory

0.39.0 is released. I'll close this one.

hierynomus avatar Sep 13 '24 19:09 hierynomus