Uploaded image for project: 'edge-inn-reach'
  1. edge-inn-reach
  2. EDGINREACH-33

Spring4Shell Lotus/Kiwi (CVE-2022-22965)

    XMLWordPrintable

Details

    • Bug
    • Status: Closed (View Workflow)
    • TBD
    • Resolution: Done
    • 1.0.3
    • 1.0.4
    • None
    • Volaris Sprint 137
    • 1
    • Volaris
    • Lotus (R1 2022) Bug Fix
    • TBD

    Description

      Lotus (R1 2022) and Kiwi (R3 2021) use edge-inn-reach 1.0.3.

      On b1.0 branch

      • upgrade spring-boot-starter-parent from 2.3.4.RELEASE to >= 2.6.6 or >= 2.5.12.RELEASE
      • or upgrade Spring Framework from 5.2.9.RELEASE to 5.2.20.RELEASE
      • or apply some other effective fix
      • or explain why edge-inn-reach is not affected by Spring4Shell.

      See FOLIO-3466

      And release a patch version.

      TestRail: Results

        Attachments

          Issue Links

            Activity

              People

                Alex1987 Aleksandr Oleinik
                julianladisch Julian Ladisch
                Votes:
                0 Vote for this issue
                Watchers:
                1 Start watching this issue

                Dates

                  Created:
                  Updated:
                  Resolved:

                  TestRail: Runs

                    TestRail: Cases