edge-common-spring 2.4.4, Spring Boot 3.2.6 fixing vulns

Description

Upgrade edge-common-spring from 2.4.3 to 2.4.4.

Upgrade Spring Boot from 3.2.3 to 3.2.6.

The Spring Boot upgrade indirectly upgrades spring-web from 6.1.4 to 6.1.8 fixing UriComponentsBuilder Open Redirect:

The Spring Boot upgrade indirectly upgrades netty-codec-http from 4.1.107.Final to 4.1.110.Final fixing form POST OOM:

CSP Request Details

See umbrella EDGCMNSPR-53 linked below, approved via EDGCMNSPR-53

CSP Rejection Details

None

Potential Workaround

None

Checklist

hide

Activity

Show:

Oleksii PetrenkoJuly 4, 2024 at 10:38 AM

Closing

Done

Details

Assignee

Reporter

Priority

Development Team

Volaris

Fix versions

Release

Quesnelia (R1 2024) Service Patch #1

RCA Group

Related dependency upgrade

CSP Approved

Yes

TestRail: Cases

Open TestRail: Cases

TestRail: Runs

Open TestRail: Runs

Created June 6, 2024 at 6:21 PM
Updated October 31, 2024 at 7:38 AM
Resolved June 25, 2024 at 2:59 PM
TestRail: Cases
TestRail: Runs