Skip to content

security: upgrade spring-security from 5.1.10 to 5.7.12#2690

Merged
yizhouxw merged 1 commit intodev/4.3.0from
security/upgrade_spring_security
Jun 6, 2024
Merged

security: upgrade spring-security from 5.1.10 to 5.7.12#2690
yizhouxw merged 1 commit intodev/4.3.0from
security/upgrade_spring_security

Conversation

@yizhouxw
Copy link
Copy Markdown
Contributor

@yizhouxw yizhouxw commented Jun 6, 2024

security: upgrade spring-security from 5.1.10 to 5.7.12, fix CVE-2024-22257

fix https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-22257

Copy link
Copy Markdown
Contributor

@yhilmare yhilmare left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@yizhouxw yizhouxw merged commit 24c53ec into dev/4.3.0 Jun 6, 2024
@yizhouxw yizhouxw deleted the security/upgrade_spring_security branch June 6, 2024 09:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

Archived in project

Development

Successfully merging this pull request may close these issues.

[Bug]: The version of Spring Security/web being used is outdated, leading to vulnerabilities that require an upgrade.

2 participants