Uploaded image for project: 'Ranger'
  1. Ranger
  2. RANGER-4038

Upgrade spring framework and spring security versions

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Open
    • Major
    • Resolution: Unresolved
    • None
    • None
    • Ranger
    • None

    Description

      Pivotal Spring Framework up to (excluding) 6.0.0 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication may be required.

      Attachments

        Issue Links

          Activity

            People

              hmaurya Himanshu Maurya
              hmaurya Himanshu Maurya
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

              Dates

                Created:
                Updated: