Uploaded image for project: 'mod-consortia'
  1. mod-consortia
  2. MODCON-29

Upgrade spring-boot-starter-actuator and spring-kafka fixing vulns

    XMLWordPrintable

Details

    • ACQ Sprint 164
    • 1
    • Thunderjet
    • Poppy (R2 2023)
    • Related dependency upgrade
    • Poppy (R2 2023)

    Description

      Upgrade spring-boot-starter-actuator from 3.0.4 to 3.0.6. This indirectly upgrades spring-boot-actuator-autoconfigure from 3.0.4 to 3.0.6 fixing Access Restriction Bypass:

      https://security.snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORKBOOT-5441321

      Upgrade spring-kafka from 3.0.4 to 3.0.6.

      Upgrading spring-kafka indirectly upgrades spring-expression from 6.0.6 to 6.0.8 fixing Allocation of Resources Without Limits or Throttling:

      https://nvd.nist.gov/vuln/detail/CVE-2023-20861
      https://nvd.nist.gov/vuln/detail/CVE-2023-20863

      Upgrading spring-kafka indirectly upgrades kafka-clients from 3.3.2 to 3.4.0 fixing Deserialization of Untrusted Data:

      https://nvd.nist.gov/vuln/detail/CVE-2023-25194

      TestRail: Results

        Attachments

          Activity

            People

              singhAdesh Adesh Singh
              julianladisch Julian Ladisch
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                TestRail: Runs

                  TestRail: Cases