Skip to content

Addressing Known High CVE Vulnerabilities in Spring #11906

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
matan504 opened this issue Feb 5, 2018 · 1 comment
Closed

Addressing Known High CVE Vulnerabilities in Spring #11906

matan504 opened this issue Feb 5, 2018 · 1 comment
Labels
status: duplicate A duplicate of another issue

Comments

@matan504
Copy link

matan504 commented Feb 5, 2018

Hi!

We use black-duck to find security vulnerabilities. The scan of the latest spring-boot 1.5.9 and 1.5.10 both show up an CVE-2017-17485 issue, sourced in jackson-databind 2.8.10.
Is there any plan to upgrade this dependency to a newer one (like 2.9.4), where the security breach was resolved?

I'd really appreciate feedback/suggestions/discussion about this.

@spring-projects-issues spring-projects-issues added the status: waiting-for-triage An issue we've not yet triaged label Feb 5, 2018
@wilkinsona
Copy link
Member

Please search existing issues before opening a new one. Duplicate of #11475.

@wilkinsona wilkinsona added status: duplicate A duplicate of another issue and removed status: waiting-for-triage An issue we've not yet triaged labels Feb 5, 2018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
status: duplicate A duplicate of another issue
Projects
None yet
Development

No branches or pull requests

3 participants