Skip to content
Snippets Groups Projects

upgrade door dependency to 1.7.0

Merge request reports

Loading
Loading

Activity

Filter activity
  • Approvals
  • Assignees & reviewers
  • Comments (from bots)
  • Comments (from users)
  • Commits & branches
  • Edits
  • Labels
  • Lock status
  • Mentions
  • Merge request status
  • Tracking
  • Henry Page requested review from @rwbackx

    requested review from @rwbackx

  • assigned to @hpage

  • Henry Page, this merge request has policy violations and errors. To unblock this merge request, fix these items:

    • Resolve all violations in the following merge request approval policies: Security check. If you think these items shouldn't be violations, ask eligible approvers of each policy to approve this merge request.

    :warning: Violations blocking this merge request


    This merge request introduces these violations:

    1. High · Bouncy Castle certificate parsing issues cause high CPU usage during parameter evaluation. · build.gradle.kts (Dependency scanning)
    2. Critical · Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT · build.gradle.kts (Dependency scanning)
    3. High · Deserialization of Untrusted Data · build.gradle.kts (Dependency scanning)
    4. Critical · Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability · build.gradle.kts (Dependency scanning)
    5. High · SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine · build.gradle.kts (Dependency scanning)
    6. High · Bouncy Castle crafted signature and public key can be used to trigger an infinite loop · build.gradle.kts (Dependency scanning)
    7. High · Bouncy Castle Java Cryptography API vulnerable to DNS poisoning · build.gradle.kts (Dependency scanning)
    8. High · jose4j uses weak cryptographic algorithm · build.gradle.kts (Dependency scanning)
    9. High · Netplex Json-smart Uncontrolled Recursion vulnerability · build.gradle.kts (Dependency scanning)
    10. High · Bouncy Castle certificate parsing issues cause high CPU usage during parameter evaluation. · build.gradle.kts (Dependency scanning)

    More violations have been detected in addition to the list above.

    :information_source: Comparison pipelines

    Edited by GitLab Security Bot
  • Ruben Backx approved this merge request

    approved this merge request

  • merged

  • Ruben Backx mentioned in commit 00656382

    mentioned in commit 00656382

Please register or sign in to reply
Loading