Admin message

On Sunday, May 30th, we will be performing critical infrastructure maintenance on our Disaster Recovery processes between 20:30 and 00:30 EDT (00:30 and 2:30 UTC). This will necessitate brief outages for Community GitLab during that time. If you are not able to access one of our services or websites, please wait a few minutes and try again. Additional status updates will be available on our status page at https://status.opengroup.org/.

Fix security vulnerabilities in legal code and legal azure modules

Vulnerability located in:

  1. tomcat-embed-core-9.0.40.jar - CVE-2021-25122 and CVE-2021-25329

  2. tomcat-embed-websocket-9.0.24.jar - CVE-2020-13935

  3. hibernate-validator-6.0.17.Final.jar - CVE-2019-10219 and CVE-2020-10693

  4. commons-codec-1.12.jar - WS-2019-0379

  5. guava-27.1-jre.jar - CVE-2020-8908

  6. spring-security-web-5.1.6.RELEASE.jar - WS-2017-3767 and WS-2016-7107 and WS-2020-0293

  7. json-smart-2.3.jar - CVE-2021-27568

  8. log4j-core-2.11.2.jar - CVE-2020-9488

  9. spring-security-core-5.1.6.RELEASE.jar - CVE-2020-5408

  10. httpclient-4.5.9.jar - CVE-2020-13956

Edited Apr 30, 2021 by Rostislav Vatolin
Assignee Loading
Time tracking Loading