Update hibernate-validator to 4.3.2

Description

To address CVE-2020-10693 & CVE-2019-10219 reported on poweredby-2023, update hibernate-validator to version 4.3.2

Acceptance / Success Criteria

None

Activity

Show:

Christian Pape May 29, 2024 at 9:53 AM

Merged.

Christian Pape May 29, 2024 at 8:08 AM

Please review:

  • PR:

Nishtha Kaura October 23, 2023 at 6:36 PM

Couple of questions here

  1. What is the source of these vulns being reported? Poweredby??

  2. Hibernate-validator 4.3 is EOL and 4.3.2 last came out in 2014. Why would we still want to upgrade to this version and not a latest version which is supported for security updates.

Fixed

Details

Assignee

Reporter

HB Grooming Date

HB Backlog Status

Sprint

Fix versions

Priority

PagerDuty

Created October 12, 2023 at 5:28 PM
Updated May 29, 2024 at 9:53 AM
Resolved May 29, 2024 at 9:53 AM