GIScience / openrouteservice

🌍 The open source route planner api with plenty of features.
https://openrouteservice.org
GNU General Public License v3.0
1.33k stars 379 forks source link

CVE-2024-22243 org.springframework:spring-web (ors.jar) #1765

Closed joewragg closed 1 month ago

joewragg commented 3 months ago

Scope

pom.xml

Report Link

https://avd.aquasec.com/nvd/cve-2024-22243

Dependency affected

org.springframework:spring-web

Proposed solution / further info

Severity: HIGH Installed version: 6.0.14 Fixed versions: 6.1.4, 6.0.17, 5.3.32 Description: springframework: URL Parsing with Host Validation

aoles commented 1 month ago

Fixed via https://github.com/GIScience/openrouteservice/pull/1788