Done
Details
Details
Assignee
Azizbek Khushvakov
Azizbek KhushvakovReporter
Mikita Siadykh
Mikita SiadykhLabels
Priority
Story Points
0.5
Sprint
None
Development Team
Thunderjet
Fix versions
Release
Poppy (R2 2023)
TestRail: Cases
Open TestRail: Cases
TestRail: Runs
Open TestRail: Runs
Created October 8, 2023 at 10:20 PM
Updated October 12, 2023 at 11:46 AM
Resolved October 12, 2023 at 11:46 AM
Upgrade to the official Spring versions: https://folio-org.atlassian.net/wiki/display/TC/Poppy#Poppy-Frameworks.1
This should include the upgrades:
spring-boot-starter-parent from 3.0.2 to >= 3.1.4
spring-cloud-starter-openfeign.version from 4.0.0 to >= 4.0.4
This fixes several security vulnerabilities in the dependencies:
https://nvd.nist.gov/vuln/detail/CVE-2023-20860
https://nvd.nist.gov/vuln/detail/CVE-2023-20873
https://nvd.nist.gov/vuln/detail/CVE-2023-20883
https://nvd.nist.gov/vuln/detail/CVE-2023-41080
https://nvd.nist.gov/vuln/detail/CVE-2023-20863
https://nvd.nist.gov/vuln/detail/CVE-2023-28709
https://nvd.nist.gov/vuln/detail/CVE-2023-28708
https://nvd.nist.gov/vuln/detail/CVE-2023-20861
https://nvd.nist.gov/vuln/detail/CVE-2023-33201