-
Notifications
You must be signed in to change notification settings - Fork 11
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Fixed Veracode security CVE-2023-46589 and CVE-2023-34053 #81
Fixed Veracode security CVE-2023-46589 and CVE-2023-34053 #81
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@amoldashwant @adityagajbhiye9 Please update change log file as per changes
@sachinargade123 @dvasunin |
- Veracode security fix.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
@almadigabor Please review and merge. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
Description
Excluded tomcat-embed-core and newer version
reason: org.apache.tomcat: tomcat-catalina(10.1.18) is vulnerable to Request Smuggling
Excluded spring-web old versions and added newer version
reason: org.springframework: spring-web (6.0.9) is vulnerable to Denial Of Service (DoS)
Pre-review checks
Please ensure to do as many of the following checks as possible, before asking for committer review: