Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade hsqldb.jar #3421

Closed
r2-lf opened this issue Oct 27, 2022 · 1 comment
Closed

Upgrade hsqldb.jar #3421

r2-lf opened this issue Oct 27, 2022 · 1 comment

Comments

@r2-lf
Copy link
Contributor

r2-lf commented Oct 27, 2022

https://nvd.nist.gov/vuln/detail/CVE-2022-41853

We are at 2.5.2 and need to upgrade to 2.7.1. This is shipped in internal/lib

Environment

Liquibase Version:

4.17.1

Liquibase Integration & Version: <Pick one: CLI, maven, gradle, spring boot, servlet, etc.>

Liquibase Extension(s) & Version:

Database Vendor & Version:

Operating System Type & Version:

Infrastructure Type/Provider: <AWC, GCS, Azure, VM, etc>

Description

A clear and concise description of the issue being addressed.

  • Describe the actual problematic behavior.
  • Ensure private information is redacted.

Steps To Reproduce

List the steps to reproduce the behavior.

  • Please be precise and ensure private information is redacted
  • Include things like
    • Files used - sql scripts, changelog file(s), property file(s), config files, POM Files
    • Exact commands used - CLI, maven, gradle, spring boot, servlet, etc.

Actual Behavior

A clear and concise description of what happens in the software with the version used.

  • Include console output if relevant
  • Include log files if available.

Expected/Desired Behavior

A clear and concise description of what happens in the software after a fix is created and merged.

Screenshots (if appropriate)

If applicable, add screenshots to help explain your problem.

Additional Context

Add any other context about the problem here.

@r2-lf
Copy link
Contributor Author

r2-lf commented Oct 27, 2022

Being handled in #3400

@r2-lf r2-lf closed this as completed Oct 27, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant