-
Notifications
You must be signed in to change notification settings - Fork 38.6k
Closed
Labels
status: declinedA suggestion or change that we don't feel we should currently applyA suggestion or change that we don't feel we should currently apply
Description
Hi,
(Apologizes if this isn't the right channel, I checked https://spring.io/security-policy but that appears to be reserved for new vulnerabilities.)
I'm part of the Debian LTS (Long Term Support) Team and I'm reviewing the security issues that affect the versions of Spring Framework shipped by Debian, so as to determine if they are vulnerable, and fix them for Debian users.
I could not find the patches/commits related to CVE-2018-1199, CVE-2018-1257, CVE-2018-1272 and CVE-2020-5421 (including through perusing the Git history).
Would it be possible to share this information?
If this is not meant to be public, could you send it privately at beuc@debian.org?
Regards,
Metadata
Metadata
Assignees
Labels
status: declinedA suggestion or change that we don't feel we should currently applyA suggestion or change that we don't feel we should currently apply