Skip to content

[UNOMI-896]: updated apache comons beanutils from 1.9.4 to 1.11.0#719

Closed
Fgerthoffert wants to merge 1 commit into
masterfrom
UNOMI-896
Closed

[UNOMI-896]: updated apache comons beanutils from 1.9.4 to 1.11.0#719
Fgerthoffert wants to merge 1 commit into
masterfrom
UNOMI-896

Conversation

@Fgerthoffert
Copy link
Copy Markdown
Contributor

Updated to a more recent version of Apache Commons beanutils, to a version not vulnerable to CVE-2025-48734

Note: We haven't investigated exposure of Unomi to that CVE via beanutils, this PR is a precaution to make sure the next unomi release does not include a version of beanutils with a vulnerability.

  • Make sure there is a JIRA issue filed
    for the change (usually before you start working on it). Trivial changes like typos do not
    require a JIRA issue. Your pull request should address just this issue, without pulling in other changes.

  • Format the pull request title like [UNOMI-XXX] - Title of the pull request

  • Run mvn clean install -P integration-tests to make sure basic checks pass. A more thorough check will be
    performed on your pull request automatically.

  • I hereby declare this contribution to be licenced under the Apache License Version 2.0, January 2004

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant