Skip to content

Commit ad88ec5

Browse files
committed
Fix Security Violations
1 parent 70eda4a commit ad88ec5

2 files changed

Lines changed: 12 additions & 25 deletions

File tree

build.gradle

Lines changed: 11 additions & 24 deletions
Original file line numberDiff line numberDiff line change
@@ -64,30 +64,17 @@ subprojects {
6464
// Force secure versions to fix vulnerabilities
6565
configurations.all {
6666
resolutionStrategy {
67-
// Use latest confirmed available Jetty 9.4.x versions - consistent versions
68-
force 'org.eclipse.jetty:jetty-server:9.4.58.v20250814'
69-
force 'org.eclipse.jetty:jetty-servlets:9.4.58.v20250814'
70-
force 'org.eclipse.jetty:jetty-http:9.4.58.v20250814'
71-
force 'org.eclipse.jetty:jetty-util:9.4.58.v20250814'
72-
force 'org.eclipse.jetty:jetty-io:9.4.58.v20250814'
73-
force 'org.eclipse.jetty:jetty-client:9.4.58.v20250814'
74-
force 'org.eclipse.jetty:jetty-security:9.4.58.v20250814'
75-
force 'org.eclipse.jetty:jetty-servlet:9.4.58.v20250814'
76-
force 'org.eclipse.jetty:jetty-webapp:9.4.58.v20250814'
77-
force 'org.eclipse.jetty:jetty-proxy:9.4.58.v20250814'
78-
force 'org.eclipse.jetty:jetty-continuation:9.4.58.v20250814'
79-
force 'org.eclipse.jetty:jetty-util-ajax:9.4.58.v20250814'
80-
force 'org.eclipse.jetty:jetty-xml:9.4.58.v20250814'
81-
force 'org.eclipse.jetty.http2:http2-server:9.4.58.v20250814'
82-
force 'org.eclipse.jetty.http2:http2-common:9.4.58.v20250814'
83-
force 'org.eclipse.jetty.http2:http2-hpack:9.4.58.v20250814'
84-
// Force ALPN modules that wiremock depends on
85-
force 'org.eclipse.jetty:jetty-alpn-server:9.4.58.v20250814'
86-
force 'org.eclipse.jetty:jetty-alpn-java-server:9.4.58.v20250814'
87-
force 'org.eclipse.jetty:jetty-alpn-openjdk8-server:9.4.58.v20250814'
88-
force 'org.eclipse.jetty:jetty-alpn-java-client:9.4.58.v20250814'
89-
force 'org.eclipse.jetty:jetty-alpn-openjdk8-client:9.4.58.v20250814'
90-
force 'org.eclipse.jetty:jetty-alpn-client:9.4.58.v20250814'
67+
// Force Jetty 12.x (used by wiremock 3.x) - fixes CVE-2026-1225
68+
force 'org.eclipse.jetty:jetty-server:12.0.12'
69+
force 'org.eclipse.jetty:jetty-http:12.0.12'
70+
force 'org.eclipse.jetty:jetty-util:12.0.12'
71+
force 'org.eclipse.jetty:jetty-io:12.0.12'
72+
force 'org.eclipse.jetty:jetty-client:12.0.12'
73+
force 'org.eclipse.jetty:jetty-util-ajax:12.0.12'
74+
force 'org.eclipse.jetty:jetty-xml:12.0.12'
75+
force 'org.eclipse.jetty.http2:http2-server:12.0.12'
76+
force 'org.eclipse.jetty.http2:http2-common:12.0.12'
77+
force 'org.eclipse.jetty.http2:http2-hpack:12.0.12'
9178
// Latest secure versions
9279
force 'commons-io:commons-io:2.18.0'
9380
force 'net.minidev:json-smart:2.5.2'

httpClient/build.gradle

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,5 +8,5 @@ repositories {
88

99
dependencies {
1010
testImplementation group: 'org.testng', name: 'testng', version: '7.5.1'
11-
testImplementation group: 'com.github.tomakehurst', name: 'wiremock-jre8', version: '2.35.0'
11+
testImplementation group: 'org.wiremock', name: 'wiremock', version: '3.12.1'
1212
}

0 commit comments

Comments
 (0)