Project

General

Profile

Actions

Bug #21103

closed

Ignore some CVE that cannot be fixed in 6.1 branch

Bug #21103: Ignore some CVE that cannot be fixed in 6.1 branch

Added by Vincent MEMBRÉ over 3 years ago. Updated over 2 years ago.

Status:
Released
Priority:
N/A
Category:
Security
Target version:
Severity:
UX impact:
User visibility:
Effort required:
Priority:
0
Name check:
To do
Fix check:
Checked
Regression:

Description

CVE-2016-1000027 and CVE-2022-22965 from our spring-core and spring-security dependencies won't be fixed in their spring minor branch, we should ignore them

Updated by Vincent MEMBRÉ over 3 years ago Actions #1

  • Status changed from New to In progress
  • Assignee set to Vincent MEMBRÉ

Updated by Vincent MEMBRÉ over 3 years ago Actions #2

  • Status changed from In progress to Pending release

Updated by Vincent MEMBRÉ over 3 years ago Actions #4

  • Fix check changed from To do to Checked

Updated by Vincent MEMBRÉ over 3 years ago Actions #5

  • Status changed from Pending release to Released

Updated by Alexis Mousset over 2 years ago Actions #6

  • Private changed from Yes to No
Actions

Also available in: PDF Atom