]> source.dussan.org Git - sonarqube.git/commitdiff
Upgrade Tomcat to 8.5.56
authorSimon Brandhof <simon.brandhof@sonarsource.com>
Mon, 22 Jun 2020 08:44:54 +0000 (10:44 +0200)
committersonartech <sonartech@sonarsource.com>
Mon, 22 Jun 2020 20:04:33 +0000 (20:04 +0000)
The vulnerability https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-9484
is not exploitable but it generates a false-positive in SCA reports.
Upgrading kills the noise.

build.gradle

index ed6859c644eb9c58b97e1e7517e083f8786c37f0..97c3a849c239e93ba11044cae06ee595a9527f6b 100644 (file)
@@ -273,7 +273,7 @@ subprojects {
         entry 'log4j-to-slf4j'
         entry 'log4j-core'
       }
-      dependencySet(group: 'org.apache.tomcat.embed', version: '8.5.53') {
+      dependencySet(group: 'org.apache.tomcat.embed', version: '8.5.56') {
         entry 'tomcat-embed-core'
         entry('tomcat-embed-jasper') {
           exclude 'org.eclipse.jdt.core.compiler:ecj'