GIScience / openrouteservice

🌍 The open source route planner api with plenty of features.
https://openrouteservice.org
GNU General Public License v3.0
1.33k stars 379 forks source link

CVE-2024-22259 org.springframework:spring-web (ors.jar) #1766

Closed joewragg closed 1 month ago

joewragg commented 3 months ago

Scope

pom.xml

Report Link

https://avd.aquasec.com/nvd/cve-2024-22259

Dependency affected

org.springframework:spring-web

Proposed solution / further info

Severity: HIGH Installed version: 6.0.14 Fixed versions: 6.1.5, 6.0.18, 5.3.33 Description: springframework: URL Parsing with Host Validation

aoles commented 1 month ago

Fixed via https://github.com/GIScience/openrouteservice/pull/1788