Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Backport 3.28] Fix CVE #2876

Merged
merged 1 commit into from Mar 24, 2023
Merged

[Backport 3.28] Fix CVE #2876

merged 1 commit into from Mar 24, 2023

Commits on Mar 24, 2023

  1. Fix CVE

        Upgrade org.springframework:spring-context@5.3.20 to org.springframework:spring-context@5.3.26 to fix
        ✗ Allocation of Resources Without Limits or Throttling (new) [Medium Severity][https://security.snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-3369749] in org.springframework:spring-expression@5.3.20
          introduced by org.springframework:spring-webmvc@5.2.22.RELEASE > org.springframework:spring-expression@5.3.20 and 3 other path(s)
    
        Upgrade org.springframework:spring-webmvc@5.2.22.RELEASE to org.springframework:spring-webmvc@5.3.26 to fix
        ✗ Allocation of Resources Without Limits or Throttling (new) [Medium Severity][https://security.snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-3369749] in org.springframework:spring-expression@5.3.20
          introduced by org.springframework:spring-webmvc@5.2.22.RELEASE > org.springframework:spring-expression@5.3.20 and 3 other path(s)
    sbrunner committed Mar 24, 2023
    Configuration menu
    Copy the full SHA
    b2ede6b View commit details
    Browse the repository at this point in the history