You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Even after upgrading to the recent 3.2.0 Spring Boot release i still get a critical vulnerability alert, because spring-ws-security still (transitively) pulls in a flagged versions.
Even after upgrading to the recent 3.2.0 Spring Boot release i still get a critical vulnerability alert, because spring-ws-security still (transitively) pulls in a flagged versions.
This pulls in several CVEs.
For example, directly in org.apache.wss4j:wss4j-ws-security-dom:jar:2.4.1
And the critically scored one from BouncyCastle:
The text was updated successfully, but these errors were encountered: