From 005c31fd1b4ac63e779f218266a898fdc79708a4 Mon Sep 17 00:00:00 2001 From: Alexander01998 Date: Wed, 13 Nov 2024 20:28:47 +0100 Subject: [PATCH] Revert "Force-update netty to patch CVE-2024-47535" Seems like we can't use that version yet? This reverts commit bd211791ac1da2e21221b7676a1a067e4ef5deb3. --- build.gradle | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/build.gradle b/build.gradle index cf8b6ae..6c6090c 100644 --- a/build.gradle +++ b/build.gradle @@ -30,13 +30,11 @@ repositories { maven {url "https://maven.terraformersmc.com/releases/"} } -// Override vulnerable dependencies until Minecraft updates to newer versions +// Override vulnerable msal4j dependency until Minecraft updates to a newer version configurations.all { resolutionStrategy { // v1.15.0, used by Minecraft 1.21.2 and 1.21.3, is vulnerable to CVE-2024-35255 force 'com.microsoft.azure:msal4j:1.17.2' - // v4.1.97, used by Minecraft 1.21.2 and 1.21.3, is vulnerable to CVE-2024-47535 - force 'io.netty:netty-common:4.1.115' } }