From ace7eacebe39a01049035210d8651015e8280b69 Mon Sep 17 00:00:00 2001 From: Adam Valenta Date: Wed, 8 Jan 2025 10:39:23 +0100 Subject: [PATCH] GH-16472 - fix CVE-2024-52046 with mina-core upgrade --- h2o-jetty-9/build.gradle | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/h2o-jetty-9/build.gradle b/h2o-jetty-9/build.gradle index 81d6cf915031..ebf33f1389ec 100644 --- a/h2o-jetty-9/build.gradle +++ b/h2o-jetty-9/build.gradle @@ -18,4 +18,10 @@ dependencies { testImplementation group: "junit", name: "junit", version: "4.12" testImplementation "org.mockito:mockito-core:2.23.0" + + constraints{ + api("org.apache.mina:mina-core:2.2.3") { + because 'Fixes CVE-2024-52046' + } + } }