Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade Spring Framework to v5.2.20 #139

Merged
merged 3 commits into from
May 16, 2023

Conversation

RonnyFrayRegato
Copy link
Collaborator

@RonnyFrayRegato RonnyFrayRegato commented Apr 15, 2023

Upgrade the Spring Framework from v4.3.23 to v5.2.20 to resolve remote code execution vulnerability.

Add javax.jms-api dependency
Remove Log4jConfigListener
@RonnyFrayRegato RonnyFrayRegato self-assigned this Apr 15, 2023
@RonnyFrayRegato RonnyFrayRegato changed the title Upgrade Spring Framework to v5.3.22 Upgrade Spring Framework to v5.2.20 May 3, 2023
@RonnyFrayRegato RonnyFrayRegato marked this pull request as ready for review May 3, 2023 20:58
Copy link
Collaborator

@brentjk brentjk left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  • checked names and syntax no obvious issues. Haven't configured these systems before so working under assumption that its how it needs to be
  • I was wondering about the log4j I know we aren't allowed to use it on other programs for vulnerabilities
  • surprised we are only updating to 5.2.20 and not straight to 6 as 5.x is end of life next December.

@jamesfwood jamesfwood merged commit 4b38fd8 into develop May 16, 2023
@jamesfwood jamesfwood deleted the IDS-9441-fix-spring-vulnerability branch May 16, 2023 23:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants