Details
-
Bug
-
Status: Closed (View Workflow)
-
TBD
-
Resolution: Done
-
None
-
CP: sprint 137
-
1
-
Core: Platform
-
TBD
Description
pac4j ships with org.apache.santuario:xmlsec@2.1.6 that contains a secureValidation XML vulnerability: https://nvd.nist.gov/vuln/detail/CVE-2021-40690
Until a fixed vertx-pac4j and pac4j version is available we need to manually upgrade xmlsec.