'Vulnerable to CVE-2022-22965 due to Spring Core dependency?

Spring Vault uses the vulnerable Spring Core components allowing Remote Code Execution (Spring4Shell). It appears the latest 2.3.2 has many vulnerable components: (https://mvnrepository.com/artifact/org.springframework.vault/spring-vault-core/2.3.2)

When should we expect 2.3.3 to be released with the latest patched components?



Sources

This article follows the attribution requirements of Stack Overflow and is licensed under CC BY-SA 3.0.

Source: Stack Overflow

Solution Source