You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A recently discovered vulnerability in Spring Framework (CVE-2022-22965) has been reported as affecting systems running with Java 9+. Note: Systems using Java 8 are not affected.
For this reason we can determine at this time that deegree webservices are not affected by this vulnerability. Spring is used within the deegree CLI utility deegree-gml-tools only. No Spring WebMVC or Spring REST controller is exposed by deegree.
Even though the deegee CLI does use a potentially vulnerable version of the Spring library we do not think it is exploitable via deegree webservices.
The deegree TMC team is aware of the reports of this vulnerability, so please do not contact us asking about it unless you are reporting an actual demonstration of the problem in a deegree installation or you are offering to assist the developer team in resolving the issue, see also Sponsoring OSGeo deegree.
A PR to upgrade Spring to a higher bugfix version has been provided, see PR #1301.
Spring Boot, Batch and Framework dependencies require update to current bug fix version (see https://spring.io/blog/2022/03/31/spring-framework-rce-early-announcement).
The text was updated successfully, but these errors were encountered: