Details
-
Bug
-
Status: Open (View Workflow)
-
Major
-
Resolution: Unresolved
-
3.5.6
-
None
-
None
Description
According to Maven Central, the latest version of MariaDB Connector/J includes a CVE vulnerability originating from its dependency on org.bouncycastle:bcpkix-jdk18on.
I see that there is a pending PR that updates the version of bcpkix-jdk18on to address this issue. Do we know when this PR is expected to be merged?
Also, the PR upgrades BouncyCastle to version 1.79, but Maven Central already contains newer versions of this library. Would it make more sense to update to the latest available version instead?