opensrp / opensrp-server-core

OpenSRP Server Core Module
Other
7 stars 6 forks source link

Patch Untrusted Java Deserialization #619

Open ndegwamartin opened 1 year ago

ndegwamartin commented 1 year ago

This issue tracks the issue https://github.com/opensrp/opensrp-server-core/security/code-scanning/245

This fix might need to await a patch from Spring given there's LTS support for Spring 5.3 till late in 2024 https://endoflife.date/spring-framework.

ndegwamartin commented 1 year ago

Supporting documentation on the CVE