Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade to Undertow 2.2.0.Final #23592

Closed
shivacharan0551 opened this issue Oct 6, 2020 · 2 comments
Closed

Upgrade to Undertow 2.2.0.Final #23592

shivacharan0551 opened this issue Oct 6, 2020 · 2 comments
Labels
status: duplicate A duplicate of another issue

Comments

@shivacharan0551
Copy link

Vulenarability

CVE-2020-10687 (https://nvd.nist.gov/vuln/detail/CVE-2020-10687) is been reported in undertow version below 2.2.0. spring-boot-starter-parent 2.3.4 is still using Undertow 2.1.4

Dependency tree
+- org.springframework.boot:spring-boot-starter-undertow:jar:2.3.4.RELEASE:compile [INFO] | +- io.undertow:undertow-core:jar:2.1.4.Final:compile

Need to upgrade and release a new update

@spring-projects-issues spring-projects-issues added the status: waiting-for-triage An issue we've not yet triaged label Oct 6, 2020
@snicoll
Copy link
Member

snicoll commented Oct 6, 2020

@shivacharan0551 please consider searching the issue tracker before opening an issue. We already upgraded in 2.4.x and already indicated in that issue why we won't upgrade to a new feature release in a maintenance release of Spring Boot.

Please reach out to the Undertow team to ask them to backport. Alternatively, you can upgrade as explained in the comment I've referenced.

@snicoll snicoll closed this as completed Oct 6, 2020
@snicoll snicoll added status: duplicate A duplicate of another issue and removed status: waiting-for-triage An issue we've not yet triaged labels Oct 6, 2020
@snicoll
Copy link
Member

snicoll commented Oct 6, 2020

Duplicate of #23367

@snicoll snicoll marked this as a duplicate of #23367 Oct 6, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
status: duplicate A duplicate of another issue
Projects
None yet
Development

No branches or pull requests

3 participants