From 675fe21e849b8edc0d132e16ec834bab664490a6 Mon Sep 17 00:00:00 2001 From: David Venable Date: Mon, 29 Jan 2024 16:29:59 -0800 Subject: [PATCH] Updates jline to 3.25.0 to resolve CVE-2023-50572. (#4020) Signed-off-by: David Venable (cherry picked from commit 8f0268bb4ac891467133096154acf42c39fd5aca) --- build.gradle | 6 ++++++ performance-test/build.gradle | 6 ++++++ 2 files changed, 12 insertions(+) diff --git a/build.gradle b/build.gradle index 490d40871d..dfbb10d3e4 100644 --- a/build.gradle +++ b/build.gradle @@ -206,6 +206,12 @@ subprojects { } because 'CVE from transitive dependencies' } + implementation('org.jline:jline') { + version { + require '3.25.0' + } + because 'CVE-2023-50572' + } implementation('org.json:json') { version { require '20231013' diff --git a/performance-test/build.gradle b/performance-test/build.gradle index 0a182966ae..70e427880c 100644 --- a/performance-test/build.gradle +++ b/performance-test/build.gradle @@ -42,6 +42,12 @@ dependencies { } because 'Fixes CVE-2023-46122' } + zinc('org.jline:jline') { + version { + require '3.25.0' + } + because 'CVE-2023-50572' + } } }