You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Even after upgrading to the recent 3.2.0 Spring Boot release i still get a critical vulnerability alert, because spring-ws-security still (transitively) pulls in a flagged versions.
Uh oh!
There was an error while loading. Please reload this page.
Even after upgrading to the recent 3.2.0 Spring Boot release i still get a critical vulnerability alert, because spring-ws-security still (transitively) pulls in a flagged versions.
This pulls in several CVEs.
For example, directly in org.apache.wss4j:wss4j-ws-security-dom:jar:2.4.1
And the critically scored one from BouncyCastle:
The text was updated successfully, but these errors were encountered: