Done
Details
Assignee
Julian LadischJulian LadischReporter
Julian LadischJulian LadischPriority
P2Development Team
VegaRelease
Morning Glory (R2 2022) Hot Fix #1RCA Group
Related dependency upgradeCSP Approved
YesTestRail: Cases
Open TestRail: CasesTestRail: Runs
Open TestRail: Runs
Details
Details
Assignee
Julian Ladisch
Julian LadischReporter
Julian Ladisch
Julian LadischPriority
Development Team
Vega
Release
Morning Glory (R2 2022) Hot Fix #1
RCA Group
Related dependency upgrade
CSP Approved
Yes
TestRail: Cases
Open TestRail: Cases
TestRail: Runs
Open TestRail: Runs
Created December 2, 2022 at 8:22 AM
Updated February 20, 2023 at 7:04 AM
Resolved December 7, 2022 at 5:30 PM
For 2022-R2 Morning Glory Hot Fix:
Upgrade spring-beans from 5.2.8.RELEASE to 5.2.22.RELEASE fixing Spring4Shell Remote Code Execution:
https://nvd.nist.gov/vuln/detail/CVE-2022-22965
Upgrade scala-library from 2.13.1 to 2.13.10 fixing Remote Code Execution (RCE):
https://nvd.nist.gov/vuln/detail/CVE-2022-36944
Before the fix:
After the fix: