Project

General

Profile

Actions

Bug #22045

closed

Rudder - Bug #22044: Spring-security is impacted by CVE-2022-31692

Spring security CVE-2022-31692 on oauth2 module

Added by François ARMAND over 1 year ago. Updated 9 months ago.

Status:
Resolved
Priority:
N/A
Target version:
Severity:
UX impact:
User visibility:
Effort required:
Priority:
0
Name check:
To do
Fix check:
To do
Regression:
No

Description

https://tanzu.vmware.com/security/cve-2022-31692

We are not impacted since we don't use spring security authorization. Still, we can update to be at the same version as parent project and avoid false positive.

Actions #1

Updated by François ARMAND over 1 year ago

  • Status changed from New to In progress
  • Assignee set to François ARMAND
Actions #2

Updated by François ARMAND over 1 year ago

  • Subject changed from Spring security CVE-2022-31692 on oauth2 module to Spring security CVE-2022-31692 on oauth2 module
  • Status changed from In progress to Resolved

It will be automatically resolved by parent, there is not specific version for oauth2 plugin, it uses rudder main one.

Actions #3

Updated by Vincent MEMBRÉ 9 months ago

  • Target version changed from 7.2-next to 7.2
Actions

Also available in: Atom PDF