Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Security: Medium severity vulnerability is detected in org.bouncycastle transitive dependency #467

@rover886

Description

@rover886

Our project's snyk scan started failing due to below Medium severity vulnerability in org.bouncycastle:[email protected].

Issues with no direct upgrade or patch:
✗ Information Exposure [Medium Severity][https://security.snyk.io/vuln/SNYK-JAVA-ORGBOUNCYCASTLE-5771489] in org.bouncycastle:[email protected]
introduced by emailconnectorapp:[email protected] > org.simplejavamail:[email protected] > org.simplejavamail:[email protected] > org.bouncycastle:[email protected] > org.bouncycastle:[email protected] and 2 other path(s)
This issue was fixed in versions: 1.74

Though we are using smime-module version 8.0.0 but I also checked for version 8.1.2 (https://mvnrepository.com/artifact/org.simplejavamail/smime-module/8.1.2) which refers to org.simplejavamail » utils-mail-smime version 2.1.1 which further refers to org.bouncycastle » bcjmail-jdk15to18 version 1.70.

bcjmail-jdk15to18 dependency should be upgraded to 1.75 to remove the vulnerability. Is there any plan for this fix?

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions