Skip to content

Commit d195814

Browse files
authored
Update shiro to 1.12.0 for CVE-2023-34478 (#7884)
1 parent e4e0aee commit d195814

File tree

5 files changed

+29
-29
lines changed

5 files changed

+29
-29
lines changed

boms/geode-all-bom/src/test/resources/expected-pom.xml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -330,7 +330,7 @@
330330
<dependency>
331331
<groupId>org.apache.shiro</groupId>
332332
<artifactId>shiro-core</artifactId>
333-
<version>1.10.0</version>
333+
<version>1.12.0</version>
334334
</dependency>
335335
<dependency>
336336
<groupId>org.assertj</groupId>

build-tools/geode-dependency-management/src/main/groovy/org/apache/geode/gradle/plugins/DependencyConstraints.groovy

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -41,7 +41,7 @@ class DependencyConstraints {
4141
deps.put("jgroups.version", "3.6.14.Final")
4242
deps.put("log4j.version", "2.17.2")
4343
deps.put("micrometer.version", "1.9.1")
44-
deps.put("shiro.version", "1.10.0")
44+
deps.put("shiro.version", "1.12.0")
4545
deps.put("slf4j-api.version", "1.7.32")
4646
deps.put("jboss-modules.version", "1.11.0.Final")
4747
deps.put("jackson.version", "2.13.3")

geode-assembly/src/integrationTest/resources/assembly_content.txt

Lines changed: 9 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -1047,15 +1047,15 @@ lib/mx4j-remote-3.0.2.jar
10471047
lib/mx4j-tools-3.0.1.jar
10481048
lib/ra.jar
10491049
lib/rmiio-2.1.2.jar
1050-
lib/shiro-cache-1.10.0.jar
1051-
lib/shiro-config-core-1.10.0.jar
1052-
lib/shiro-config-ogdl-1.10.0.jar
1053-
lib/shiro-core-1.10.0.jar
1054-
lib/shiro-crypto-cipher-1.10.0.jar
1055-
lib/shiro-crypto-core-1.10.0.jar
1056-
lib/shiro-crypto-hash-1.10.0.jar
1057-
lib/shiro-event-1.10.0.jar
1058-
lib/shiro-lang-1.10.0.jar
1050+
lib/shiro-cache-1.12.0.jar
1051+
lib/shiro-config-core-1.12.0.jar
1052+
lib/shiro-config-ogdl-1.12.0.jar
1053+
lib/shiro-core-1.12.0.jar
1054+
lib/shiro-crypto-cipher-1.12.0.jar
1055+
lib/shiro-crypto-core-1.12.0.jar
1056+
lib/shiro-crypto-hash-1.12.0.jar
1057+
lib/shiro-event-1.12.0.jar
1058+
lib/shiro-lang-1.12.0.jar
10591059
lib/slf4j-api-1.7.32.jar
10601060
lib/slf4j-api-1.7.36.jar
10611061
lib/snappy-0.4.jar

geode-assembly/src/integrationTest/resources/gfsh_dependency_classpath.txt

Lines changed: 9 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -47,8 +47,8 @@ antlr-2.7.7.jar
4747
istack-commons-runtime-4.0.1.jar
4848
jaxb-impl-2.3.2.jar
4949
commons-validator-1.7.jar
50-
shiro-core-1.10.0.jar
51-
shiro-config-ogdl-1.10.0.jar
50+
shiro-core-1.12.0.jar
51+
shiro-config-ogdl-1.12.0.jar
5252
commons-beanutils-1.9.4.jar
5353
commons-codec-1.15.jar
5454
commons-collections-3.2.2.jar
@@ -69,13 +69,13 @@ jna-platform-5.11.0.jar
6969
jna-5.11.0.jar
7070
snappy-0.4.jar
7171
jgroups-3.6.14.Final.jar
72-
shiro-cache-1.10.0.jar
73-
shiro-crypto-hash-1.10.0.jar
74-
shiro-crypto-cipher-1.10.0.jar
75-
shiro-config-core-1.10.0.jar
76-
shiro-event-1.10.0.jar
77-
shiro-crypto-core-1.10.0.jar
78-
shiro-lang-1.10.0.jar
72+
shiro-cache-1.12.0.jar
73+
shiro-crypto-hash-1.12.0.jar
74+
shiro-crypto-cipher-1.12.0.jar
75+
shiro-config-core-1.12.0.jar
76+
shiro-event-1.12.0.jar
77+
shiro-crypto-core-1.12.0.jar
78+
shiro-lang-1.12.0.jar
7979
slf4j-api-1.7.36.jar
8080
spring-beans-5.3.21.jar
8181
javax.activation-api-1.2.0.jar

geode-server-all/src/integrationTest/resources/dependency_classpath.txt

Lines changed: 9 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,8 @@
11
spring-web-5.3.21.jar
2-
shiro-event-1.10.0.jar
3-
shiro-crypto-hash-1.10.0.jar
4-
shiro-crypto-cipher-1.10.0.jar
5-
shiro-config-core-1.10.0.jar
2+
shiro-event-1.12.0.jar
3+
shiro-crypto-hash-1.12.0.jar
4+
shiro-crypto-cipher-1.12.0.jar
5+
shiro-config-core-1.12.0.jar
66
commons-digester-2.1.jar
77
commons-validator-1.7.jar
88
spring-jcl-5.3.21.jar
@@ -23,11 +23,11 @@ geode-cq-0.0.0.jar
2323
geode-old-client-support-0.0.0.jar
2424
javax.servlet-api-3.1.0.jar
2525
jgroups-3.6.14.Final.jar
26-
shiro-cache-1.10.0.jar
26+
shiro-cache-1.12.0.jar
2727
httpcore-4.4.15.jar
2828
spring-beans-5.3.21.jar
2929
lucene-queries-6.6.6.jar
30-
shiro-core-1.10.0.jar
30+
shiro-core-1.12.0.jar
3131
HikariCP-4.0.3.jar
3232
slf4j-api-1.7.32.jar
3333
geode-http-service-0.0.0.jar
@@ -63,7 +63,7 @@ jetty-io-9.4.47.v20220610.jar
6363
geode-deployment-legacy-0.0.0.jar
6464
commons-beanutils-1.9.4.jar
6565
log4j-core-2.17.2.jar
66-
shiro-crypto-core-1.10.0.jar
66+
shiro-crypto-core-1.12.0.jar
6767
jaxb-api-2.3.1.jar
6868
geode-unsafe-0.0.0.jar
6969
spring-shell-1.2.0.RELEASE.jar
@@ -73,14 +73,14 @@ log4j-jul-2.17.2.jar
7373
HdrHistogram-2.1.12.jar
7474
jackson-annotations-2.13.3.jar
7575
micrometer-core-1.9.1.jar
76-
shiro-config-ogdl-1.10.0.jar
76+
shiro-config-ogdl-1.12.0.jar
7777
geode-log4j-0.0.0.jar
7878
lucene-analyzers-phonetic-6.6.6.jar
7979
spring-context-5.3.21.jar
8080
jetty-security-9.4.47.v20220610.jar
8181
geode-logging-0.0.0.jar
8282
commons-io-2.11.0.jar
83-
shiro-lang-1.10.0.jar
83+
shiro-lang-1.12.0.jar
8484
javax.transaction-api-1.3.jar
8585
geode-common-0.0.0.jar
8686
antlr-2.7.7.jar

0 commit comments

Comments
 (0)