irods-contrib / metalnx-web

Metalnx Web Application
https://metalnx.github.io/
BSD 3-Clause "New" or "Revised" License
36 stars 36 forks source link

Vulnerability spring4shell #307

Open rudibroekhuizen opened 2 years ago

rudibroekhuizen commented 2 years ago

Is metalnx vulnerable for the sping4shell security issue? Package spring-core-4.3.18.RELEASE.jar is used in the code. See https://github.com/NCSC-NL/spring4shell.

trel commented 2 years ago

Putting this in 3.0.0, we will bump all the dependencies... along with the refactor / removal of the metalnx database.