Advisory ID: SUSE-SU-2023:2097-1 Released: Thu May 4 09:11:06 2023 Summary: Security update for maven and recommended update for antlr3, minlog, sbt, xmvn Type: security Severity: important Advisory ID: SUSE-SU-2023:2111-1 Released: Fri May 5 14:34:00 2023 Summary: Security update for ncurses Type: security Severity: moderate Advisory ID: SUSE-RU-2023:2131-1 Released: Tue May 9 13:35:24 2023
References : 1193795 1206513 1207014 1210434 CVE-2021-42550 CVE-2023-29491
1193795,CVE-2021-42550
This update for antlr3, maven, minlog, sbt, xmvn fixes the following issues:
maven:
- Version update from 3.8.5 to 3.8.6 (jsc#SLE-23217):
* Security fixes:
+ CVE-2021-42550: Update Version of (optional) Logback (bsc#1193795)
* Bug fixes:
+ Fix resolver session containing non-MavenWorkspaceReader
+ Fix for multiple maven instances working on same source tree that can lock each other
+ Don't ignore bin/ otherwise bin/ in apache-maven module cannot be added back
+ Fix IllegalStateException in SessionScope during guice injection in multithreaded build
+ Revert MNG-7347 (SessionScoped beans should be singletons for a given session)
+ Fix compilation failure with relocated transitive dependency
Get the latest Linux and open source security news straight to your inbox.