Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
chore(dependency): upgrade nimbus-jose to fix CVE-2023-52428 (#1194)
`com.nimbusds:nimbus-jose-jwt` dependency is pinned to version 7.9, that is very old version and shows [CVE-2023-52428](https://nvd.nist.gov/vuln/detail/CVE-2023-52428) as direct vulnerability. In order to fix this vulnerability upgrading and pinning nimbus-jose to 9.37.2. The components using nimbus-jose as direct or transitive dependency are gate, clouddriver, front50 and halyard.
- Loading branch information