Skip to content
This repository was archived by the owner on May 14, 2025. It is now read-only.

[CVE-2024-25710] Security issues in transitive dependency of commons-compress 1.24.0 (SPRING-CLOUD-DATAFLOW 2.11.2) #5719

Closed
obaSAP opened this issue Mar 4, 2024 · 1 comment
Assignees
Labels
area/dependencies Belongs project dependencies

Comments

@obaSAP
Copy link

obaSAP commented Mar 4, 2024

Hello,

We've found the following security issue in the transitive dependency of commons-compress 1.24.0 in version 2.11.2.
https://www.mend.io/vulnerability-database/CVE-2024-25710
Would appreciate your kind assistance with fixing the issue.

Thanks & BR,
Omri.

@github-actions github-actions bot added the status/need-triage Team needs to triage and take a first look label Mar 4, 2024
corneil pushed a commit to corneil/spring-cloud-dataflow that referenced this issue Mar 4, 2024
@corneil corneil self-assigned this Mar 4, 2024
@corneil corneil added area/dependencies Belongs project dependencies and removed status/need-triage Team needs to triage and take a first look labels Mar 4, 2024
corneil pushed a commit that referenced this issue Mar 4, 2024
@corneil
Copy link
Contributor

corneil commented Mar 5, 2024

PR merged

@corneil corneil closed this as completed Mar 5, 2024
corneil pushed a commit that referenced this issue Apr 10, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
area/dependencies Belongs project dependencies
Development

No branches or pull requests

2 participants