Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

KARAF-6721 - Update Spring versions due to CVE-2020-5398 #1118

Merged
merged 1 commit into from May 18, 2020
Merged

KARAF-6721 - Update Spring versions due to CVE-2020-5398 #1118

merged 1 commit into from May 18, 2020

Conversation

coheigea
Copy link
Contributor

No description provided.

Comment on lines 303 to 304
<spring43.version>4.3.25.RELEASE_1</spring43.version>
<spring50.version>5.0.15.RELEASE_1</spring50.version>
Copy link
Member

@skitt skitt May 14, 2020

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ideally these should be upgraded too (5.0.16 addressed the same CVE, and 4.3.27 includes a backport of related fixes), but there are no corresponding ServiceMix bundles.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yeah, I saw that there were no corresponding bundles, or I would have included those too.

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm preparing SMX bundles releases about that.

@jbonofre jbonofre self-requested a review May 17, 2020 04:26
@jbonofre
Copy link
Member

retest this please

@jbonofre jbonofre merged commit 2af2008 into apache:master May 18, 2020
@coheigea coheigea deleted the KARAF-6721 branch May 18, 2020 08:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
4 participants