Skip to main content


Eclipse Community Forums
Forum Search:

Search      Help    Register    Login    Home
Home » Eclipse Projects » EGit / JGit » Security issue: CVE-2023-4759 on Java 8(How to fix CVE-2023-4759 on jgit)
Security issue: CVE-2023-4759 on Java 8 [message #1862132] Tue, 14 November 2023 14:55 Go to next message
Abbas Kassem Moussa is currently offline Abbas Kassem MoussaFriend
Messages: 2
Registered: November 2023
Junior Member
Hello team,
We use JGIT in our project and currently we are on Jgit 5.8, however we have a security concern (https://www.eclipse.org/forums/index.php?/r/frm_id/48/??SQ=ba5e6eb6365ec54b61d94f4096f24728&S=dc9affae313c8c7b2458f5e70afedd04).

This issue was fixed on 6.6.1 however this requires java 11, we're currently on Java 8 and we can't upgrade to java 11.
Is there a patch on older versions that fixes this issue while still supporting java 8?
Re: Security issue: CVE-2023-4759 on Java 8 [message #1863007 is a reply to message #1862132] Wed, 10 January 2024 20:58 Go to previous messageGo to next message
Matthias Sohn is currently offline Matthias SohnFriend
Messages: 1268
Registered: July 2009
Senior Member
Chao Wang downported the fix to stable-5.13, see https://eclipse.gerrithub.io/c/eclipse-jgit/jgit/+/204642
I can release 5.13.3 soon.
Re: Security issue: CVE-2023-4759 on Java 8 [message #1863023 is a reply to message #1863007] Thu, 11 January 2024 08:23 Go to previous messageGo to next message
Abbas Kassem Moussa is currently offline Abbas Kassem MoussaFriend
Messages: 2
Registered: November 2023
Junior Member
Hello!

Thanks a lot for this, it's a very good news for us! .
Is there a release date expected for 5.13.3?

Best,
Abbas

[Updated on: Thu, 11 January 2024 08:36]

Report message to a moderator

Re: Security issue: CVE-2023-4759 on Java 8 [message #1863339 is a reply to message #1863023] Sat, 27 January 2024 16:57 Go to previous message
Matthias Sohn is currently offline Matthias SohnFriend
Messages: 1268
Registered: July 2009
Senior Member
5.13.3 was released on Jan 11, see https://projects.eclipse.org/projects/technology.jgit/releases/5.13.3
Previous Topic:local eclipse php project git repository clone to another local directory
Next Topic:JGit Merge Test
Goto Forum:
  


Current Time: Mon Apr 15 22:28:53 GMT 2024

Powered by FUDForum. Page generated in 0.07630 seconds
.:: Contact :: Home ::.

Powered by: FUDforum 3.0.2.
Copyright ©2001-2010 FUDforum Bulletin Board Software

Back to the top