-
Notifications
You must be signed in to change notification settings - Fork 469
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[WFCORE-6676] CVE-2023-48795 Upgrade Apache Mina SSHD to 2.12.0 #5844
Conversation
Core -> Full Integration Build 13430 outcome was FAILURE using a merge of d74b7b8 |
Core -> Full Integration Build 13191 outcome was FAILURE using a merge of d74b7b8 |
Core -> WildFly Preview Integration Build 13254 outcome was FAILURE using a merge of d74b7b8 |
Hello @yersan , is there something wrong with the full integration tests? They fail with following, which I think is not caused by the changes in the commit:
|
Hi @TomasHofman , you caught the WildFly Core repo in the middle of a release with the CI Jobs not updated yet. They are already modified, so it is just a matter of kicking them off again. CI is going pretty slow to me now, but I'll kick them later |
That's great @yersan , thanks for info! :) |
@TomasHofman Done, let's see how they go. In case you want to know when they are in progress, you can check this Zulip stream where we advertise when we are releasing: https://wildfly.zulipchat.com/#narrow/stream/274477-Pull-requests/topic/WildFly.20Core.20Release |
@TomasHofman we are going to need another PR for |
@yersan I only need it in main and 21.0.x (for EAP). |
@TomasHofman no problem, it is more a matter of getting the CVE resolved for all current releases upstream and unrelated to the product. I've backported it to 23.x |
Thanks @TomasHofman |
Thanks @yersan ! |
https://issues.redhat.com/browse/WFCORE-6676
Resolves CVE-2023-48795 / apache/mina-sshd#445