We have received multiple CVE tickets against Spring-Core used in grails services where the grails-gradle-plugin is a must have:
CVE-2023-20860CVE-2023-20863
However we are not able to override the SpringBoot/SpringFramework version because of the dependency import from the plugin dominates the versions.
Please provide configurations to manually set the dependency versions to resolve CVEs as necessary, or if it is configurable instructions are deeply appreciated.
We have received multiple CVE tickets against Spring-Core used in grails services where the grails-gradle-plugin is a must have: CVE-2023-20860 CVE-2023-20863 However we are not able to override the SpringBoot/SpringFramework version because of the dependency import from the plugin dominates the versions.
Please provide configurations to manually set the dependency versions to resolve CVEs as necessary, or if it is configurable instructions are deeply appreciated.