holodeck-b2b / Holodeck-B2B

Holodeck B2B is an AS4 system-to-system messaging solution that implements the OASIS specifications for ebMS3 and it's AS4 profile. For more information visit the project website

Home Page:http://holodeck-b2b.org

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

CVEs in outdated libs wss4j and xmlsec

sopgreg opened this issue · comments

The versions used for wss4j (2.2.2) and xmlsec (2.1.2) are several years old and partially also contain CVEs.

grafik

See also:

https://ws.apache.org/wss4j/index.html
https://santuario.apache.org/secadv.html

We will be upgrading dependencies in a future version. However, these CVEs are in parts of the libraries that Holodeck B2B does not use and therefore do not pose a risk.