Details
-
Bug
-
Status: Closed (View Workflow)
-
P2
-
Resolution: Done
-
1.13.3, 1.14.1, 1.14.2, 1.14.3
-
-
1
-
Folijet
-
Nolana (R3 2022)
-
Related dependency upgrade
Description
Upgrade folio-di-support from 1.4.1 to 1.6.0.
This indirectly upgrades Spring and spring-beans from 5.2.8 to 5.3.20 fixing Remote Code Execution: https://nvd.nist.gov/vuln/detail/CVE-2022-22965
Upgrade Vert.x from 4.3.1 to 4.3.3 fixing SSL in WebClient: https://github.com/vert-x3/wiki/wiki/4.3.2-Release-Notes#vertx-web
TestRail: Results
Attachments
Issue Links
- blocks
-
FOLIO-3466 Spring4Shell: spring-beans RCE Vulnerability (CVE-2022-22965)
-
- Closed
-
- defines
-
UXPROD-3557 NFR: Data Import Technical, NFR, & Misc work (Nolana R3 2022)
-
- Closed
-
- relates to
-
MODDICONV-279 Spring 5.2.22 fixing vulnerabilities (Spring4Shell, etc.) MG
-
- Closed
-