From 8f9b489297476f630b3bdde9143c78f679f2d35f Mon Sep 17 00:00:00 2001 From: Christian Pape Date: Thu, 26 Sep 2024 07:57:36 +0200 Subject: [PATCH] NMS-16515: Excluding vulnerable esapi version --- dependencies/spring-security/pom.xml | 19 +++++++++++++++++++ pom.xml | 1 + 2 files changed, 20 insertions(+) diff --git a/dependencies/spring-security/pom.xml b/dependencies/spring-security/pom.xml index 0a979edb8b80..a1ac25ff015d 100644 --- a/dependencies/spring-security/pom.xml +++ b/dependencies/spring-security/pom.xml @@ -98,6 +98,25 @@ org.apache.santuario xmlsec + + org.owasp.esapi + esapi + + + + + org.owasp.esapi + esapi + ${esapiVersion} + + + xml-apis + * + + + log4j + log4j + diff --git a/pom.xml b/pom.xml index 2f615e12c1bc..5724f858e7a1 100644 --- a/pom.xml +++ b/pom.xml @@ -1661,6 +1661,7 @@ 0.3.0 4.1.69.Final 7.6.2 + 2.3.0.0 4.0.12 3.0.6 2.9