Repository navigation
fix(deps): update dependency com.microsoft.sqlserver:mssql-jdbc to v10 [security] - #382
Conversation
|
I'm unsure why Renovate suggests such an old version. We have been using mssql-jdbc-13.2.1.jre11 in prod for over a year (and are planning to upgrade to the latest version 13.4.0 as we speak). JDK support for all versions is similar, newer is better: https://learn.microsoft.com/en-us/sql/connect/jdbc/microsoft-jdbc-driver-for-sql-server-support-matrix?view=sql-server-ver17#java-and-jdbc-specification-support SQL server support is the same for all versions: https://learn.microsoft.com/en-us/sql/connect/jdbc/microsoft-jdbc-driver-for-sql-server-support-matrix?view=sql-server-ver17#sql-version-compatibility |
Agreed, but progress is progress. |
226871a to
feed9f5
Compare
@jbeckers My guess is because this is a security update, and that is the lowest version that is not affected by the named CVE. I'm sure we would entertain a PR that upgrades the library to something more current, especially if it's already well tested in your environment. |
This PR contains the following updates:
8.4.1.jre8→10.2.4.jre11JDBC Driver for SQL Server has improper input validation issue
CVE-2025-59250 / GHSA-m494-w24q-6f7w
More information
Details
Improper input validation in JDBC Driver for SQL Server allows an unauthorized attacker to perform spoofing over a network.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:NReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Configuration
📅 Schedule: (in timezone America/New_York)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.