Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Commons IO dependency affected by CVE-2024-47554 #1145

Open
ThomasVitale opened this issue Oct 6, 2024 · 0 comments · May be fixed by #1146
Open

Commons IO dependency affected by CVE-2024-47554 #1145

ThomasVitale opened this issue Oct 6, 2024 · 0 comments · May be fixed by #1146
Labels
status/need-triage Team needs to triage and take a first look

Comments

@ThomasVitale
Copy link

The spring-shell-core module uses commons-io:commons-io:2.11.0 which is affected by CVE-2024-47554.
The solution is to upgrade to version 2.14+

@github-actions github-actions bot added the status/need-triage Team needs to triage and take a first look label Oct 6, 2024
ThomasVitale added a commit to ThomasVitale/spring-shell that referenced this issue Oct 6, 2024
Fixes spring-projectsgh-1145

Signed-off-by: Thomas Vitale <ThomasVitale@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
status/need-triage Team needs to triage and take a first look
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant