Skip to content

CVE-2022-22980 Update Spring Data Stack due to CVE in MongoDB integration #31492

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
ghenadiibatalski opened this issue Jun 22, 2022 · 5 comments
Labels
status: duplicate A duplicate of another issue

Comments

@ghenadiibatalski
Copy link

Hello,
we use currently Spring Boot Stack 2.6.8 with MongoDB integration. Please update the Spring Data Stack to 3.3.5+ as described by https://tanzu.vmware.com/security/cve-2022-22980

Many thanks and best regards,

G. Batalski

@spring-projects-issues spring-projects-issues added the status: waiting-for-triage An issue we've not yet triaged label Jun 22, 2022
@bclozel
Copy link
Member

bclozel commented Jun 22, 2022

Duplicates #31349

@bclozel bclozel closed this as not planned Won't fix, can't repro, duplicate, stale Jun 22, 2022
@bclozel bclozel added status: duplicate A duplicate of another issue and removed status: waiting-for-triage An issue we've not yet triaged labels Jun 22, 2022
@bclozel bclozel pinned this issue Jun 22, 2022
@mbimbij
Copy link

mbimbij commented Jun 22, 2022

naive question:

i know i can declare the spring-data-mongo dependency on its own,
but is a spring-boot release with the upgraded dependency scheduled soon ?

so that i could just ask devs to upgrade spring-boot to 2.7.1 or 2.6.9 ?

Thank you

@markbigler
Copy link
Contributor

You can find the milestones with their scheduled date here: https://github.com/spring-projects/spring-boot/milestones

Both, 2.6.9 and 2.7.1, are scheduled for tomorrow.

@snicoll
Copy link
Member

snicoll commented Jun 22, 2022

@mbimbij Brian closed the issue with a reference to an issue that provides you that information.

@mbimbij

This comment was marked as resolved.

@wilkinsona wilkinsona unpinned this issue Oct 5, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
status: duplicate A duplicate of another issue
Projects
None yet
Development

No branches or pull requests

6 participants