Actions
Bug #22045
closedRudder - Bug #22044: Spring-security is impacted by CVE-2022-31692
Spring security CVE-2022-31692 on oauth2 module
Pull Request:
Severity:
UX impact:
User visibility:
Effort required:
Priority:
0
Name check:
To do
Fix check:
To do
Regression:
No
Description
https://tanzu.vmware.com/security/cve-2022-31692
We are not impacted since we don't use spring security authorization. Still, we can update to be at the same version as parent project and avoid false positive.
Actions