WebCuratorTool / webcurator

The root of the webcurator tool project, containing all modules needed to run a fully functional webcurator tool.
Apache License 2.0
2 stars 1 forks source link

Fix for CVE-2022-22965 #68

Closed hannakoppelaar closed 1 year ago

hannakoppelaar commented 2 years ago

This PR contains the fix for the Spring4Shell vulnerability (CVE-2022-22965). At the time of writing WCT does not appear to be affected by this issue, since it seems that only deployments inside Tomcat are vulnerable. However, the impact might still turn out to be larger, so it's a good idea to fix this ASAP, in order to be ready to release a patch version if necessary.

leefrank9527 commented 2 years ago

Reviewd and complie the PR. It works fine.