-
Couldn't load subscription status.
- Fork 813
Closed
Labels
dependenciesPull requests that update a dependency filePull requests that update a dependency file
Milestone
Description
By using Spring boot 3.4.2 and Spring Cloud (2024.0.0) one of its dependencies is Apache Commons IO (2.11.0). Any schedule to update to its lates considering that 2.11.0 version got a CVE (https://mvnrepository.com/artifact/commons-io/commons-io/2.11.0)?
More details:
GHSA-78wr-2p64-hpwj
Thanks in advance.
Zernov-A and tr4l
Metadata
Metadata
Assignees
Labels
dependenciesPull requests that update a dependency filePull requests that update a dependency file