-
Notifications
You must be signed in to change notification settings - Fork 6.1k
Closed
Labels
status: blockedAn issue that's blocked on an external project changeAn issue that's blocked on an external project change
Description
Expected Behavior
I would like if minor version 5.4 was available, which does not fail security analysis tools. Currently CWE-862 seems to not be fixed earlier than 5.6, but unfortunately we are unable to migrate to Spring Boot 5.5 at the moment.
These ones seem to be related:
#9931
#9795
Current Behavior
./gradlew dependencyCheckAnalyze fails with following error:
spring-security-core-5.4.9.jar (pkg:maven/org.springframework.security/spring-security-core@5.4.9, cpe:2.3:a:pivotal_sof
tware:spring_security:5.4.9:*:*:*:*:*:*:*) : CWE-862: Missing Authorization
Context
We are not able to build our project anymore because of this security problem.
Metadata
Metadata
Assignees
Labels
status: blockedAn issue that's blocked on an external project changeAn issue that's blocked on an external project change