Uploaded image for project: 'mod-source-record-manager'
  1. mod-source-record-manager
  2. MODSOURMAN-923

Spring 5.2.22 fixing Spring4Shell CVE-2022-22965 (MG)

    XMLWordPrintable

Details

    • Folijet Sprint 155
    • 0
    • Folijet
    • Morning Glory (R2 2022) Hot Fix #1
    • Related dependency upgrade

    Description

      mod-source-record-manager 3.4.5 is used for Morning Glory platform-complete.

      mod-source-record-manager 3.4.5 comes with the runtime dependency spring-beans 5.2.8.RELEASE that has the Spring4Shell Remote Code Execution vulnerability, for details see FOLIO-3466 and https://nvd.nist.gov/vuln/detail/CVE-2022-22965 .

      Fix: Upgrade Spring Framework from 5.2.8.RELEASE to 5.2.22.RELEASE.

      And release as Morning Glory Hot Fix.

      Note: This issue is for fixing Spring4Shell in Morning Glory only. For Nolana (and Orchid) it has been fixed with MODSOURMAN-889.

      TestRail: Results

        Attachments

          Issue Links

            Activity

              People

                julianladisch Julian Ladisch
                julianladisch Julian Ladisch
                Votes:
                0 Vote for this issue
                Watchers:
                4 Start watching this issue

                Dates

                  Created:
                  Updated:
                  Resolved:

                  TestRail: Runs

                    TestRail: Cases