diff --git a/CHANGELOG.md b/CHANGELOG.md index 240ac07511a33..91e442ddf8734 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -7,6 +7,7 @@ Inspired from [Keep a Changelog](https://keepachangelog.com/en/1.0.0/) ### Added ### Dependencies - OpenJDK Update (April 2024 Patch releases), update to Eclipse Temurin 11.0.23+9 ([#13406](https://github.com/opensearch-project/OpenSearch/pull/13406)) +- Upgrade BouncyCastle dependencies from 1.75 to 1.78.1 resolving [CVE-2024-30172], [CVE-2024-30171] and [CVE-2024-29857] ### Changed ### Deprecated diff --git a/buildSrc/version.properties b/buildSrc/version.properties index 973b95f0739cb..e81f527f32397 100644 --- a/buildSrc/version.properties +++ b/buildSrc/version.properties @@ -35,7 +35,7 @@ jetty = 9.4.53.v20231009 # when updating this version, you need to ensure compatibility with: # - plugins/ingest-attachment (transitive dependency, check the upstream POM) # - distribution/tools/plugin-cli -bouncycastle=1.75 +bouncycastle=1.78.1 # test dependencies randomizedrunner = 2.7.1 junit = 4.13.2 diff --git a/plugins/ingest-attachment/licenses/bcmail-jdk15to18-1.75.jar.sha1 b/plugins/ingest-attachment/licenses/bcmail-jdk15to18-1.75.jar.sha1 deleted file mode 100644 index e6840a9b02b38..0000000000000 --- a/plugins/ingest-attachment/licenses/bcmail-jdk15to18-1.75.jar.sha1 +++ /dev/null @@ -1 +0,0 @@ -b316bcd094e3917b1ece93a6edbab93f8315fb3b \ No newline at end of file diff --git a/plugins/ingest-attachment/licenses/bcmail-jdk15to18-1.78.1.jar.sha1 b/plugins/ingest-attachment/licenses/bcmail-jdk15to18-1.78.1.jar.sha1 new file mode 100644 index 0000000000000..21374feedaa87 --- /dev/null +++ b/plugins/ingest-attachment/licenses/bcmail-jdk15to18-1.78.1.jar.sha1 @@ -0,0 +1 @@ +4ec9c0125a605408da16cf8758cc75b502204cbb diff --git a/plugins/ingest-attachment/licenses/bcpkix-jdk15to18-1.75.jar.sha1 b/plugins/ingest-attachment/licenses/bcpkix-jdk15to18-1.75.jar.sha1 deleted file mode 100644 index 9181b1c3ab1b6..0000000000000 --- a/plugins/ingest-attachment/licenses/bcpkix-jdk15to18-1.75.jar.sha1 +++ /dev/null @@ -1 +0,0 @@ -f16e5252ad7a46d5eaf255231b0a5da307599082 \ No newline at end of file diff --git a/plugins/ingest-attachment/licenses/bcpkix-jdk15to18-1.78.1.jar.sha1 b/plugins/ingest-attachment/licenses/bcpkix-jdk15to18-1.78.1.jar.sha1 new file mode 100644 index 0000000000000..3a1d2a1e24c96 --- /dev/null +++ b/plugins/ingest-attachment/licenses/bcpkix-jdk15to18-1.78.1.jar.sha1 @@ -0,0 +1 @@ +5884ee847542641d04abfbfdeca3446d0300670b diff --git a/plugins/ingest-attachment/licenses/bcprov-jdk15to18-1.75.jar.sha1 b/plugins/ingest-attachment/licenses/bcprov-jdk15to18-1.75.jar.sha1 deleted file mode 100644 index 9911bb75f9209..0000000000000 --- a/plugins/ingest-attachment/licenses/bcprov-jdk15to18-1.75.jar.sha1 +++ /dev/null @@ -1 +0,0 @@ -df22e1b6a9f6b218913f5b68dd16641344397fe0 \ No newline at end of file diff --git a/plugins/ingest-attachment/licenses/bcprov-jdk15to18-1.78.1.jar.sha1 b/plugins/ingest-attachment/licenses/bcprov-jdk15to18-1.78.1.jar.sha1 new file mode 100644 index 0000000000000..393c2246b2756 --- /dev/null +++ b/plugins/ingest-attachment/licenses/bcprov-jdk15to18-1.78.1.jar.sha1 @@ -0,0 +1 @@ +83bfa8229f7127d933161aefb281e54a9ffcf9f4