Bug #19410
closed
Bug #19407: CVE in spring dependency
Remaining spring dependencies with CVE impacted version
Added by François ARMAND over 3 years ago.
Updated over 3 years ago.
Description
We still have some 5.2.13 dependencies:
11:12:09 [ERROR] spring-beans-5.2.13.RELEASE.jar: CVE-2021-22118
- Target version set to 6.1.14
- Status changed from New to In progress
- Assignee set to François ARMAND
- Status changed from In progress to Pending technical review
- Assignee changed from François ARMAND to Alexis Mousset
- Pull Request set to https://github.com/Normation/rudder/pull/3672
- Status changed from Pending technical review to Pending release
- Fix check changed from To do to Checked
- Status changed from Pending release to Released
This bug has been fixed in Rudder 6.1.14 and 6.2.8 which were released today.
Also available in: Atom
PDF