File tree Expand file tree Collapse file tree 2 files changed +9
-1
lines changed Expand file tree Collapse file tree 2 files changed +9
-1
lines changed Original file line number Diff line number Diff line change @@ -14,7 +14,12 @@ dependencies {
14
14
implementation project(" :contract" )
15
15
implementation project(" :serde-api" )
16
16
implementation libs. spring. starter. webflux
17
- implementation libs. spring. starter. security
17
+ implementation(libs. spring. starter. security){
18
+ exclude group : ' com.nimbusds' , module : ' nimbus-jose-jwt' because(" Temporary overwrite to fix CVE-2025-5386. See https://avd.aquasec.com/nvd/2025/cve-2025-53864/" )
19
+ }
20
+ implementation(libs. nimbus. jose. jwt){
21
+ because(" Fixes CVE-2025-5386. See https://avd.aquasec.com/nvd/2025/cve-2025-53864/" )
22
+ }
18
23
implementation libs. spring. starter. actuator
19
24
implementation libs. spring. starter. logging
20
25
implementation libs. spring. starter. oauth2. client
Original file line number Diff line number Diff line change 1
1
[versions ]
2
2
spring-boot = ' 3.5.3'
3
+ nimbus-jose-jwt = ' 10.0.2'
3
4
4
5
aws-msk-auth = ' 2.3.0'
5
6
azure-identity = ' 1.15.4'
@@ -60,6 +61,8 @@ spring-starter-actuator = { module = 'org.springframework.boot:spring-boot-start
60
61
spring-starter-test = { module = ' org.springframework.boot:spring-boot-starter-test' , version.ref = ' spring-boot' }
61
62
spring-starter-webflux = { module = ' org.springframework.boot:spring-boot-starter-webflux' , version.ref = ' spring-boot' }
62
63
spring-starter-security = { module = ' org.springframework.boot:spring-boot-starter-security' , version.ref = ' spring-boot' }
64
+ # Temporary overwrite to fix CVE-2025-5386
65
+ nimbus-jose-jwt = { module = ' com.nimbusds:nimbus-jose-jwt' , version.ref = ' nimbus-jose-jwt' }
63
66
spring-starter-validation = { module = ' org.springframework.boot:spring-boot-starter-validation' , version.ref = ' spring-boot' }
64
67
spring-starter-oauth2-client = { module = ' org.springframework.boot:spring-boot-starter-oauth2-client' , version.ref = ' spring-boot' }
65
68
spring-starter-logging = { module = ' org.springframework.boot:spring-boot-starter-logging' , version.ref = ' spring-boot' }
You can’t perform that action at this time.
0 commit comments