Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Commons IO dependency affected by CVE-2024-47554 #1145

Closed
ThomasVitale opened this issue Oct 6, 2024 · 1 comment
Closed

Commons IO dependency affected by CVE-2024-47554 #1145

ThomasVitale opened this issue Oct 6, 2024 · 1 comment
Labels
status/need-triage Team needs to triage and take a first look

Comments

@ThomasVitale
Copy link

The spring-shell-core module uses commons-io:commons-io:2.11.0 which is affected by CVE-2024-47554.
The solution is to upgrade to version 2.14+

@github-actions github-actions bot added the status/need-triage Team needs to triage and take a first look label Oct 6, 2024
ThomasVitale added a commit to ThomasVitale/spring-shell that referenced this issue Oct 6, 2024
@corneil
Copy link

corneil commented Dec 10, 2024

Bumped to 2.18.0

@corneil corneil closed this as completed Dec 10, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
status/need-triage Team needs to triage and take a first look
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants