Project

General

Profile

Actions

Bug #21103

closed

Ignore some CVE that cannot be fixed in 6.1 branch

Added by Vincent MEMBRÉ over 2 years ago. Updated over 1 year ago.

Status:
Released
Priority:
N/A
Category:
Security
Target version:
Severity:
UX impact:
User visibility:
Effort required:
Priority:
0
Name check:
To do
Fix check:
Checked
Regression:

Description

CVE-2016-1000027 and CVE-2022-22965 from our spring-core and spring-security dependencies won't be fixed in their spring minor branch, we should ignore them

Actions #1

Updated by Vincent MEMBRÉ over 2 years ago

  • Status changed from New to In progress
  • Assignee set to Vincent MEMBRÉ
Actions #2

Updated by Vincent MEMBRÉ over 2 years ago

  • Status changed from In progress to Pending release
Actions #4

Updated by Vincent MEMBRÉ over 2 years ago

  • Fix check changed from To do to Checked
Actions #5

Updated by Vincent MEMBRÉ over 2 years ago

  • Status changed from Pending release to Released
Actions #6

Updated by Alexis Mousset over 1 year ago

  • Private changed from Yes to No
Actions

Also available in: Atom PDF