Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update SpringFramework for Spring RCE #8734

Closed
emeroad opened this issue Apr 1, 2022 · 0 comments · Fixed by #8735 or #8748
Closed

Update SpringFramework for Spring RCE #8734

emeroad opened this issue Apr 1, 2022 · 0 comments · Fixed by #8735 or #8748
Assignees
Labels
dependencies Pull requests that update a dependency file security
Milestone

Comments

@emeroad
Copy link
Member

emeroad commented Apr 1, 2022

Notice

Pinpoint is deployed as a Spring-Boot executable jar, so there is currently no vulnerability.

https://spring.io/blog/2022/03/31/spring-framework-rce-early-announcement

spring-framework 5.3.13 ->5.3.18
spring-boot 2.5.7->2.5.12

@emeroad emeroad added this to the 2.4.0 milestone Apr 1, 2022
@emeroad emeroad self-assigned this Apr 1, 2022
@emeroad emeroad pinned this issue Apr 1, 2022
emeroad added a commit to emeroad/pinpoint that referenced this issue Apr 1, 2022
@emeroad emeroad linked a pull request Apr 1, 2022 that will close this issue
@emeroad emeroad reopened this Apr 1, 2022
emeroad added a commit to emeroad/pinpoint that referenced this issue Apr 5, 2022
@emeroad emeroad linked a pull request Apr 5, 2022 that will close this issue
@emeroad emeroad added the dependencies Pull requests that update a dependency file label Apr 6, 2022
@emeroad emeroad closed this as completed Apr 20, 2022
@emeroad emeroad unpinned this issue Apr 22, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file security
Projects
None yet
1 participant