eclipse / hawkbit

Eclipse hawkBit™
https://projects.eclipse.org/projects/iot.hawkbit
Eclipse Public License 2.0
444 stars 186 forks source link

Vulnerabilities detected for certain packages. #1758

Open shreyaskulkarni-bh opened 1 week ago

shreyaskulkarni-bh commented 1 week ago

Hi Team,

The following vulnerabilities were detected. will these be addressed in the new milestones?

<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:x="urn:schemas-microsoft-com:office:excel" xmlns="http://www.w3.org/TR/REC-html40">

PackageName | Package version | CVE | Severity -- | -- | -- | -- expat | 2.5.0-r2 | CVE-2023-52425 | HIGH spring-security-core | 6.2.2 | CVE-2024-22257 | HIGH spring-web | 6.1.4 | CVE-2024-22262 | HIGH spring-web | 6.1.4 | CVE-2024-22259 | HIGH

Regards, Shreyas Kulkarni

strailov commented 6 days ago

Hello @shreyaskulkarni-bh ! Thanks for using hawkBit! Can you specify which version of hawkBit are you using ? Thanks!