Done
Details
Details
Assignee
Kurt Nordstrom
Kurt NordstromReporter
Julian Ladisch
Julian LadischPriority
Sprint
None
Development Team
Thor
Fix versions
Release
Nolana (R3 2022) Bug Fix
RCA Group
Related dependency upgrade
TestRail: Cases
Open TestRail: Cases
TestRail: Runs
Open TestRail: Runs
Created August 24, 2022 at 6:51 PM
Updated July 13, 2023 at 2:49 PM
Resolved October 27, 2022 at 11:13 AM
mod-ldp uses spring-boot 2.3.1 (org.springframework.boot:spring-boot-starter-parent:2.3.1.RELEASE).
This version has reached end of open source support on 2021-05-20 and end of commercial support on 2022-08-20: https://spring.io/projects/spring-boot/#support
Please upgrade to spring-boot 2.7.
This will fix many vulnerabilities, including
Denial of Service (DoS) in jackson-databind https://nvd.nist.gov/vuln/detail/CVE-2020-36518
Improper Input Validation in org.glassfish:jakarta.el https://nvd.nist.gov/vuln/detail/CVE-2021-28170
Spring4Shell (FOLIO-3466) Remote Code Execution in spring-beans https://nvd.nist.gov/vuln/detail/CVE-2022-22965
Remote Code Execution in tomcat-embed-core https://nvd.nist.gov/vuln/detail/CVE-2021-25329