-
Notifications
You must be signed in to change notification settings - Fork 56
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update Spring IO Platform 1.1.5+ on 5.0.x line #392
Comments
Framework Stack
Others (test scope or provided scope)
|
Related bug will be fix at next release (4.1.9). |
Another vulnerability like commons-collections was found in Spring 4 and fixed in 4.1.9. We must adopt 4.1.9 for next 5.0.2.RELEASE. (I fixed the subject of this issue) |
Keep eyes on IO Platform 1.1.5. |
https://spring.io/blog/2015/12/17/spring-framework-4-2-4-4-1-9-released |
Spring IO Platform 1.1.5.RELEASE has been released. |
Spring IO Platform 1.1.5.RELEASE includes Apache Commons Collection 3.2.2 whose vulnerability was fixed. |
* Apply fix version for CVE-2015-5211 * Apply fix version for COLLECTIONS-580
…orm-1.1.5 Update to Spring IO Platform 1.1.5 #392
Description
Fix http://pivotal.io/security/cve-2015-5211.
https://jira.spring.io/browse/SPR-13656
Possible Solutions
Update spring version.
Note:
We will consider whether applying Spring IO Platform 1.1.5+.
But if no new IOPF is released, we override Spring version by ourselves.Affects Version/s
Fix Version/s
Issue Links
The text was updated successfully, but these errors were encountered: