Re: Proposal to backport GEODE-8167

2020-05-21 Thread Owen Nichols
Done! > On May 21, 2020, at 9:50 AM, Dave Barnes wrote: > > Please add this change to support/1.13, Owen. > Thanks, > Dave > > On 2020/05/21 16:19:49, Dick Cavender wrote: >> +1 >> >> On Thu, May 21, 2020 at 8:57 AM Ju@N wrote: >> >>> +1 >>> >>> On Thu, 21 May 2020 at 16:53, Anthony Baker

Re: Proposal to backport GEODE-8167

2020-05-21 Thread Dave Barnes
Please add this change to support/1.13, Owen. Thanks, Dave On 2020/05/21 16:19:49, Dick Cavender wrote: > +1 > > On Thu, May 21, 2020 at 8:57 AM Ju@N wrote: > > > +1 > > > > On Thu, 21 May 2020 at 16:53, Anthony Baker wrote: > > > > > +1 > > > > > > > On May 21, 2020, at 8:51 AM, Owen Nichol

Re: Proposal to backport GEODE-8167

2020-05-21 Thread Udo Kohlmeyer
+1 On May 21, 2020, 8:51 AM -0700, Owen Nichols , wrote: Some automated scans have flagged Geode Pulse as potentially containing “high" security vulnerability CVE-2020-5407. Analysis shows that this saml vulnerability is not applicable to Geode Pulse. It is low risk to bump the spring-security d

Re: Proposal to backport GEODE-8167

2020-05-21 Thread Dick Cavender
+1 On Thu, May 21, 2020 at 8:57 AM Ju@N wrote: > +1 > > On Thu, 21 May 2020 at 16:53, Anthony Baker wrote: > > > +1 > > > > > On May 21, 2020, at 8:51 AM, Owen Nichols wrote: > > > > > > Some automated scans have flagged Geode Pulse as potentially containing > > “high" security vulnerability C

Re: Proposal to backport GEODE-8167

2020-05-21 Thread Ju@N
+1 On Thu, 21 May 2020 at 16:53, Anthony Baker wrote: > +1 > > > On May 21, 2020, at 8:51 AM, Owen Nichols wrote: > > > > Some automated scans have flagged Geode Pulse as potentially containing > “high" security vulnerability CVE-2020-5407. > > > > Analysis shows that this saml vulnerability is

Re: Proposal to backport GEODE-8167

2020-05-21 Thread Anthony Baker
+1 > On May 21, 2020, at 8:51 AM, Owen Nichols wrote: > > Some automated scans have flagged Geode Pulse as potentially containing > “high" security vulnerability CVE-2020-5407. > > Analysis shows that this saml vulnerability is not applicable to Geode Pulse. > > It is low risk to bump the spr

Proposal to backport GEODE-8167

2020-05-21 Thread Owen Nichols
Some automated scans have flagged Geode Pulse as potentially containing “high" security vulnerability CVE-2020-5407. Analysis shows that this saml vulnerability is not applicable to Geode Pulse. It is low risk to bump the spring-security dependency to the latest version to avoid false positives