Xavier Fernandis created HBASE-30298:
----------------------------------------
Summary: Bump Jruby to 9.4.15.0 to address multiple CVE's.
Key: HBASE-30298
URL: https://issues.apache.org/jira/browse/HBASE-30298
Project: HBase
Issue Type: Task
Reporter: Xavier Fernandis
Assignee: Xavier Fernandis
*There are some of the vulnerabilites fix in 9.4.15.0*
CVE-2025-14813
CVE-2026-41316
CVE-2026-5598
sonatype-2025-001911
CVE-2026-5588
CVE-2026-0636
CVE-2025-58767
Upgraded jruby 9.4.14.0 → 9.4.15.0 to remediate the BouncyCastle CVEs flagged
in this finding: jruby-complete embeds BC as nested jars in its
stdlib (1.79), which Maven dependency management cannot override, so the
bundled copy was only upgradable via the jruby bump.
Post-upgrade jruby ships BC 1.84 — aligned with HBase's existing 1.84 — with
joni (2.2.5) and jcodings (1.0.63) verified unchanged and compatible.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)