Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix CVE-2023-44483 Vulnerability in Ballerina SOAP Module #113

Merged
merged 7 commits into from
Nov 3, 2023

Conversation

Nuvindu
Copy link
Contributor

@Nuvindu Nuvindu commented Nov 3, 2023

Purpose

This aims at resolving CVE-2023-44483, a security vulnerability that affects the Apache Santuario - XML Security for Java library, which is utilized by the Ballerina SOAP module as an external dependency. The vulnerability could potentially lead to private key disclosure when generating an XML Signature and enabling debug-level logging.

To fix this vulnerability, the Apache Santuario - XML Security for Java library is updated to version 3.0.3. This update will ensure the the security of the Ballerina SOAP module.

Copy link

codecov bot commented Nov 3, 2023

Codecov Report

All modified and coverable lines are covered by tests ✅

Comparison is base (d8daae1) 96.33% compared to head (730df9b) 96.33%.

Additional details and impacted files
@@           Coverage Diff           @@
##           master     #113   +/-   ##
=======================================
  Coverage   96.33%   96.33%           
=======================================
  Files          12       12           
  Lines         409      409           
  Branches      283      283           
=======================================
  Hits          394      394           
  Misses         15       15           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

native/build.gradle Outdated Show resolved Hide resolved
@dilanSachi dilanSachi merged commit 894f3bd into ballerina-platform:master Nov 3, 2023
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants