[
https://issues.apache.org/jira/browse/HBASE-30298?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
ASF GitHub Bot updated HBASE-30298:
-----------------------------------
Labels: pull-request-available (was: )
> Bump Jruby to 9.4.15.0 to address multiple CVE's.
> -------------------------------------------------
>
> Key: HBASE-30298
> URL: https://issues.apache.org/jira/browse/HBASE-30298
> Project: HBase
> Issue Type: Task
> Reporter: Xavier Fernandis
> Assignee: Xavier Fernandis
> Priority: Major
> Labels: pull-request-available
>
> *There are some of the vulnerabilites fix in 9.4.15.0*
> CVE-2025-14813
> CVE-2026-41316
> CVE-2026-5598
> sonatype-2025-001911
> CVE-2026-5588
> CVE-2026-0636
> CVE-2025-58767
> Upgraded jruby 9.4.14.0 → 9.4.15.0 to remediate the BouncyCastle CVEs flagged
> in this finding: jruby-complete embeds BC as nested jars in its
> stdlib (1.79), which Maven dependency management cannot override, so the
> bundled copy was only upgradable via the jruby bump.
> Post-upgrade jruby ships BC 1.84 — aligned with HBase's existing 1.84 — with
> joni (2.2.5) and jcodings (1.0.63) verified unchanged and compatible.
>
--
This message was sent by Atlassian Jira
(v8.20.10#820010)