Composer Dependency Changed PR-4.4-dev Pending

User tests: Successful: Unsuccessful:

avatar SniperSister
SniperSister
5 Dec 2023

Summary of Changes

Update phpseclib to 3.0.34 to fix https://nvd.nist.gov/vuln/detail/CVE-2023-49316.

Testing Instructions

Code review.

avatar SniperSister SniperSister - open - 5 Dec 2023
avatar SniperSister SniperSister - change - 5 Dec 2023
Status New Pending
avatar joomla-cms-bot joomla-cms-bot - change - 5 Dec 2023
Category External Library Composer Change
avatar richard67
richard67 - comment - 20 Dec 2023

This will also fix issue #42142 . See also my PR #42190 for that issue, which I've just closed in favour of this one here.

avatar richard67 richard67 - test_item - 20 Dec 2023 - Tested successfully
avatar richard67
richard67 - comment - 20 Dec 2023

I have tested this item ✅ successfully on a518908

Tested by code review + verified that the URL is correct.


This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/42470.

avatar rdeutz
rdeutz - comment - 20 Dec 2023

Shouldn't we have also an update for composer.json, we have still "phpseclib/bcmath_compat": "^2.0.1"

avatar SniperSister
SniperSister - comment - 20 Dec 2023

How is bcmath related to the PR @rdeutz ?

avatar richard67
richard67 - comment - 29 Dec 2023

@SniperSister Meanwhile there is a new release 3.0.35 available. Changelog see https://github.com/phpseclib/phpseclib/releases/tag/3.0.35 . Would it make sense to update this PR to that release?

avatar SniperSister
SniperSister - comment - 31 Dec 2023

@richard67 as we have updated to 3.0.34 in the 5.x branch I would suggest we do the same here.

avatar MacJoom MacJoom - change - 19 Feb 2024
Labels Added: Composer Dependency Changed PR-4.4-dev
avatar MacJoom MacJoom - change - 19 Feb 2024
Status Pending Fixed in Code Base
Closed_Date 0000-00-00 00:00:00 2024-02-19 11:53:47
Closed_By MacJoom
avatar MacJoom MacJoom - close - 19 Feb 2024
avatar MacJoom MacJoom - merge - 19 Feb 2024
avatar MacJoom
MacJoom - comment - 19 Feb 2024

Thank you!

Add a Comment

Login with GitHub to post a comment