Merge 1.5.3 changes back to master.

This commit is contained in:
Mike Jumper
2023-06-10 21:22:11 -07:00
16 changed files with 33 additions and 16 deletions

View File

@@ -77,7 +77,7 @@
<dependency>
<groupId>org.springframework.security</groupId>
<artifactId>spring-security-web</artifactId>
<version>5.8.2</version>
<version>5.8.3</version>
</dependency>
</dependencies>

View File

@@ -74,6 +74,23 @@
<groupId>com.onelogin</groupId>
<artifactId>java-saml</artifactId>
<version>2.9.0</version>
<!--
Replace vulnerable version of Woodstox until upstream
releases a version with fixed dependencies
-->
<exclusions>
<exclusion>
<groupId>com.fasterxml.woodstox</groupId>
<artifactId>woodstox-core</artifactId>
</exclusion>
</exclusions>
</dependency>
<!-- Woodstox -->
<dependency>
<groupId>com.fasterxml.woodstox</groupId>
<artifactId>woodstox-core</artifactId>
<version>5.4.0</version>
</dependency>
</dependencies>