-
Notifications
You must be signed in to change notification settings - Fork 122
Please update Bouncy Castle #175
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Comments
The AWS Encryption SDK for Java is not impacted by CVE-2019-17359 as the BouncyCastle ASN.1 parser is only used on data that we generate and control. Nevertheless, we can update BouncyCastle and will schedule that for the next release. |
@WesleyRosenblum: Thanks for your PR. It is better to have last version of librairies, not only Bouncy Castle. |
Couldn't agree more. :) |
@WesleyRosenblum, @robin-aws: Can you look and do a new update? |
Please update Bouncy Castle
The text was updated successfully, but these errors were encountered: