Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

bcprov-jdk15on高危安全漏洞 #223

Open
buaazyl opened this issue Oct 25, 2024 · 6 comments
Open

bcprov-jdk15on高危安全漏洞 #223

buaazyl opened this issue Oct 25, 2024 · 6 comments

Comments

@buaazyl
Copy link

buaazyl commented Oct 25, 2024

如题,请升级依赖版本

@Dzkol
Copy link
Collaborator

Dzkol commented Oct 30, 2024

已升级bcprov-jdk15on版本

@buaazyl
Copy link
Author

buaazyl commented Oct 30, 2024

bcprov-jdk15on 漏洞太多,而且也不更新了,为啥不升级到bcprov-jdk18on呢

@Dzkol
Copy link
Collaborator

Dzkol commented Oct 30, 2024

升级bcprov-jdk18on目前已经在评估和排期中了哈

@leshalv
Copy link

leshalv commented Nov 3, 2024

#176 @Dzkol

@leshalv
Copy link

leshalv commented Nov 3, 2024

#103 都好久了,一年都要过去了,本身该SDK起步就是1.8,升级应该没有多费劲吧!

@Dzkol
Copy link
Collaborator

Dzkol commented Feb 7, 2025

方案评审过程中,由于评估到直接升级可能会导致存量客户出现兼容性问题,因此暂不进行该操作。短期内您可以在引入cos java sdk时把jdk15on的包添加到exclusion里,然后额外引入jdk18on的包来解决。例如:

<dependency>
            <groupId>com.qcloud</groupId>
            <artifactId>cos_api</artifactId>
            <version>5.6.231</version>
	     <exclusions>
                <exclusion>
                    <groupId>org.bouncycastle</groupId>
                    <artifactId>bcprov-jdk15on</artifactId>
                </exclusion>
            </exclusions>
</dependency>
<dependency>
            <groupId>org.bouncycastle</groupId>
            <artifactId>bcprov-jdk18on</artifactId>
            <version>1.79</version>
</dependency>

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants