Lotus: Spring4Shell (CVE-2022-22965)

Description

Update Spring from 2.6.3 to 2.6.6.

This fixes these vulnerabilities:

CSP Request Details

None

CSP Rejection Details

None

Potential Workaround

None

Checklist

hide

TestRail: Results

Activity

Show:

Julian LadischMay 13, 2022 at 6:45 AM

Checking that the Docker container actually contains the upgraded libraries:

These are fixed versions, therefore I close as done. Thanks!

Natalia ZaitsevaMay 12, 2022 at 3:15 PM
Edited

already released and deployed to lotus bugfest  can you review and probably close the issue?

 

Julian LadischApril 26, 2022 at 10:56 PM

No, it has already been merged to master.

Khalilah GambrellApril 26, 2022 at 10:51 PM

Thanks.  do we need to create a user story for this work to be done in Morning Glory too?

Julian LadischApril 26, 2022 at 10:28 PM

Yes, it fixes remote code execution vulnerabilities that should be released with next Lotus hotfix.

Done

Details

Assignee

Reporter

Priority

Development Team

Spitfire

Fix versions

Release

Lotus (R1 2022) Hot Fix #1

RCA Group

Related dependency upgrade

TestRail: Cases

Open TestRail: Cases

TestRail: Runs

Open TestRail: Runs

Created April 22, 2022 at 12:16 PM
Updated May 13, 2022 at 6:45 AM
Resolved April 26, 2022 at 10:34 PM
TestRail: Cases
TestRail: Runs