'Vulnerable to CVE-2022-22965 due to Spring Core dependency?
Spring Vault uses the vulnerable Spring Core components allowing Remote Code Execution (Spring4Shell). It appears the latest 2.3.2 has many vulnerable components: (https://mvnrepository.com/artifact/org.springframework.vault/spring-vault-core/2.3.2)
When should we expect 2.3.3 to be released with the latest patched components?
Sources
This article follows the attribution requirements of Stack Overflow and is licensed under CC BY-SA 3.0.
Source: Stack Overflow
| Solution | Source |
|---|
