Skip to content

Commit 8500d92

Browse files
committed
chore(deps): enforce newer Jetty version for Spark (CVE-2023-44487, CVE-2023-36478)
1 parent 5aacfe5 commit 8500d92

File tree

1 file changed

+13
-0
lines changed
  • aws-serverless-java-container-spark

1 file changed

+13
-0
lines changed

aws-serverless-java-container-spark/pom.xml

+13
Original file line numberDiff line numberDiff line change
@@ -19,6 +19,19 @@
1919
<spark.version>2.9.4</spark.version>
2020
</properties>
2121

22+
<dependencyManagement>
23+
<dependencies>
24+
<!-- outdated transitive dependency in spark-core (CVE-2023-44487, CVE-2023-36478) -->
25+
<dependency>
26+
<groupId>org.eclipse.jetty</groupId>
27+
<artifactId>jetty-bom</artifactId>
28+
<version>9.4.53.v20231009</version>
29+
<type>pom</type>
30+
<scope>import</scope>
31+
</dependency>
32+
</dependencies>
33+
</dependencyManagement>
34+
2235
<dependencies>
2336
<!-- Core interfaces for the aws-serverless-java-container project -->
2437
<dependency>

0 commit comments

Comments
 (0)