Skip to content

RUN-3786: CVE-2025-41249 false positive#1705

Merged
fdevans merged 1 commit into4.0.xfrom
RUN-3786
Sep 24, 2025
Merged

RUN-3786: CVE-2025-41249 false positive#1705
fdevans merged 1 commit into4.0.xfrom
RUN-3786

Conversation

@ronaveva
Copy link
Contributor

No description provided.

@ronaveva ronaveva added this to the 5.15.0 milestone Sep 24, 2025
@ronaveva ronaveva requested review from Copilot and fdevans September 24, 2025 19:49
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR documents CVE-2025-41249 as a false positive for Rundeck products and fixes a minor grammatical error in another CVE document. The changes clarify that Rundeck is not vulnerable to this Spring Framework security issue because it doesn't use the affected annotation.

Reviewed Changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated 1 comment.

File Description
docs/history/cves/index.md Adds CVE-2025-41249 to the CVE index list
docs/history/cves/cve-2025-41249.md Creates new documentation page explaining the false positive status
docs/history/cves/cve-2025-41242.md Fixes grammatical error by removing duplicate "disable" word

@@ -0,0 +1,13 @@
---
order: 53
Copy link

Copilot AI Sep 24, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The order value '53' appears incorrect. Based on the existing CVE documents, CVE-2025-41242 has order 51 and CVE-2025-48924 likely has order 52, so this should be order 52 or the sequence needs verification to ensure proper ordering.

Suggested change
order: 53
order: 52

Copilot uses AI. Check for mistakes.
@fdevans fdevans merged commit 860ce39 into 4.0.x Sep 24, 2025
2 checks passed
@fdevans fdevans deleted the RUN-3786 branch September 24, 2025 19:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants