Uploaded image for project: 'CXF'
  1. CXF
  2. CXF-8687

Version 3.4.6 contains vulnerable spring version

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Critical
    • Resolution: Not A Bug
    • 3.4.6
    • None
    • Core
    • None
    • Unknown

    Description

      Version 3.4.6 contains the vulnerable spring core version 5.2.19, containing this CVE:

      CVE-2022-22965: Spring Framework RCE via Data Binding on JDK 9+

       

      I do see this commit where the proper version of spring is referenced:

      https://github.com/apache/cxf/commit/0f8b5a2c2a66ab62c931096aaf512390d58fef3d

       

      Any chance this will be released quickly as 3.4.7?

      Attachments

        Activity

          People

            Unassigned Unassigned
            mveurman Mathieu Veurman
            Votes:
            1 Vote for this issue
            Watchers:
            4 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: