Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Apache commons-io version update #1146

Open
trcoelho opened this issue Jan 27, 2025 · 1 comment
Open

Apache commons-io version update #1146

trcoelho opened this issue Jan 27, 2025 · 1 comment

Comments

@trcoelho
Copy link

By using Spring boot 3.4.2 and Spring Cloud (2024.0.0) one of its dependencies is Apache Commons IO (2.11.0). Any schedule to update to its lates considering that 2.11.0 version got a CVE (https://mvnrepository.com/artifact/commons-io/commons-io/2.11.0)?

More details:
GHSA-78wr-2p64-hpwj

Thanks in advance.

@tr4l
Copy link

tr4l commented Jan 31, 2025

+1

Also dependanbot seems to have already updated the library, so "only" a release seems to be needed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants