Skip to content

fix(deps): update dependency org.hsqldb:hsqldb to v2.7.1 [security]#2671

Merged
bjagg merged 1 commit into
masterfrom
renovate/hsqldbversion
Apr 23, 2026
Merged

fix(deps): update dependency org.hsqldb:hsqldb to v2.7.1 [security]#2671
bjagg merged 1 commit into
masterfrom
renovate/hsqldbversion

Conversation

@renovate

@renovate renovate Bot commented Jun 10, 2023

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
org.hsqldb:hsqldb (source) 2.5.12.7.1 age confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


HyperSQL DataBase vulnerable to remote code execution when processing untrusted input

CVE-2022-41853 / GHSA-77xx-rxvh-q682

More information

Details

Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb (HyperSQL DataBase) to process untrusted input may be vulnerable to a remote code execution attack. By default it is allowed to call any static method of any Java class in the classpath resulting in code execution. The issue can be prevented by updating to 2.7.1 or by setting the system property "hsqldb.method_class_names" to classes which are allowed to be called. For example, System.setProperty("hsqldb.method_class_names", "abc") or Java argument -Dhsqldb.method_class_names="abc" can be used. From version 2.7.1 all classes by default are not accessible except those in java.lang.Math and need to be manually enabled.

Severity

  • CVSS Score: 9.8 / 10 (Critical)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • ""
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot changed the title fix(deps): update dependency org.hsqldb:hsqldb to v2.7.2 Update dependency org.hsqldb:hsqldb to v2.7.2 Aug 2, 2023
@renovate renovate Bot changed the title Update dependency org.hsqldb:hsqldb to v2.7.2 fix(deps): update dependency org.hsqldb:hsqldb to v2.7.2 Aug 10, 2023
@renovate renovate Bot force-pushed the renovate/hsqldbversion branch from ed58701 to fb0564d Compare August 22, 2023 17:44
@renovate renovate Bot changed the title fix(deps): update dependency org.hsqldb:hsqldb to v2.7.2 Update dependency org.hsqldb:hsqldb to v2.7.2 Aug 22, 2023
@renovate renovate Bot changed the title Update dependency org.hsqldb:hsqldb to v2.7.2 fix(deps): update dependency org.hsqldb:hsqldb to v2.7.2 Oct 26, 2023
@bjagg

bjagg commented Nov 10, 2023

Copy link
Copy Markdown
Member

v2.7.1 and later requires Java 11

@bjagg bjagg added the Java11+ Requires Java 11+, so waiting for uPortal 6 label Nov 10, 2023
@renovate renovate Bot force-pushed the renovate/hsqldbversion branch 2 times, most recently from 05bf7e4 to 97c96e6 Compare November 16, 2023 11:38
@renovate renovate Bot changed the title fix(deps): update dependency org.hsqldb:hsqldb to v2.7.2 fix(deps): update dependency org.hsqldb:hsqldb to v2.7.3 May 31, 2024
@renovate renovate Bot force-pushed the renovate/hsqldbversion branch from 97c96e6 to 63dc078 Compare May 31, 2024 07:00
@renovate renovate Bot force-pushed the renovate/hsqldbversion branch from 63dc078 to cfda382 Compare August 27, 2024 04:15
@renovate renovate Bot changed the title fix(deps): update dependency org.hsqldb:hsqldb to v2.7.3 fix(deps): update dependency org.hsqldb:hsqldb to v2.7.4 Nov 3, 2024
@renovate renovate Bot force-pushed the renovate/hsqldbversion branch from cfda382 to 7d313d8 Compare November 3, 2024 01:54
@renovate renovate Bot force-pushed the renovate/hsqldbversion branch from 7d313d8 to 31b144e Compare February 19, 2025 03:28
@renovate renovate Bot force-pushed the renovate/hsqldbversion branch from 31b144e to 283a9d1 Compare March 3, 2025 11:51
@renovate renovate Bot force-pushed the renovate/hsqldbversion branch from 283a9d1 to c5299a3 Compare April 30, 2025 16:00
@renovate renovate Bot force-pushed the renovate/hsqldbversion branch from c5299a3 to 6453961 Compare August 10, 2025 13:35
@renovate renovate Bot force-pushed the renovate/hsqldbversion branch from 6453961 to 1633b81 Compare December 30, 2025 12:43
@renovate renovate Bot force-pushed the renovate/hsqldbversion branch from 1633b81 to 5965172 Compare February 27, 2026 13:17
@renovate renovate Bot force-pushed the renovate/hsqldbversion branch from 5965172 to 89d57ad Compare March 13, 2026 15:20
@renovate renovate Bot force-pushed the renovate/hsqldbversion branch from 89d57ad to 9c61ba7 Compare April 1, 2026 17:16
@renovate renovate Bot force-pushed the renovate/hsqldbversion branch from 9c61ba7 to 79437fb Compare April 8, 2026 17:16
@renovate renovate Bot changed the title fix(deps): update dependency org.hsqldb:hsqldb to v2.7.4 fix(deps): update dependency org.hsqldb:hsqldb to v2.7.1 [security] Apr 15, 2026
@renovate renovate Bot force-pushed the renovate/hsqldbversion branch from 79437fb to f503114 Compare April 15, 2026 09:00
@bjagg bjagg merged commit dcc92ab into master Apr 23, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Java11+ Requires Java 11+, so waiting for uPortal 6

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant