Project

General

Profile

Actions

Bug #21103

closed

Ignore some CVE that cannot be fixed in 6.1 branch

Added by Vincent MEMBRÉ almost 2 years ago. Updated 9 months ago.

Status:
Released
Priority:
N/A
Category:
Security
Target version:
Severity:
UX impact:
User visibility:
Effort required:
Priority:
0
Name check:
To do
Fix check:
Checked
Regression:

Description

CVE-2016-1000027 and CVE-2022-22965 from our spring-core and spring-security dependencies won't be fixed in their spring minor branch, we should ignore them

Actions

Also available in: Atom PDF