Skip to content

Conversation

@qinlonglong123
Copy link
Contributor

@qinlonglong123 qinlonglong123 commented Oct 21, 2025

Due to JDK version constraints, Spring Boot cannot be upgraded further. Therefore, tomcat-embed-core can only be upgraded to 9.0.108 to address the CVE-2025-48989 vulnerability.
Fixes: #4985
Follow this checklist to help us incorporate your contribution quickly and easily:

  • Make sure there is a JIRA issue filed for the change (usually before you start working on it). Trivial changes like typos do not require a JIRA issue. Your pull request should address just this issue, without pulling in other changes.
  • Each commit in the pull request should have a meaningful subject line and body.
  • Format the pull request title like [SCB-XXX] Fixes bug in ApproximateQuantiles, where you replace SCB-XXX with the appropriate JIRA issue.
  • Write a pull request description that is detailed enough to understand what the pull request does, how, and why.
  • Run mvn clean install -Pit to make sure basic checks pass. A more thorough check will be performed on your pull request automatically.
  • If this contribution is large, please file an Apache Individual Contributor License Agreement.

Due to JDK version constraints, Spring Boot cannot be upgraded further. Therefore, tomcat-embed-core can only be upgraded to 9.0.108 to address the CVE-2025-48989 vulnerability.
@qinlonglong123 qinlonglong123 changed the title upgrade org.apache.tomcat.embed:tomcat-embed-core to 9.0.108 [#4985] upgrade org.apache.tomcat.embed:tomcat-embed-core to 9.0.108 Oct 21, 2025
@qinlonglong123
Copy link
Contributor Author

@chengyouling
please help review this PR. Thank you.

@SweetWuXiaoMei
Copy link
Member

我看没啥问题

@SweetWuXiaoMei SweetWuXiaoMei merged commit 88774b8 into apache:2.8.x Oct 22, 2025
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants