paulschwarz / spring-dotenv

Provides a Dotenv property source for Spring
MIT License
325 stars 23 forks source link

CVE in SpringFramework #10

Closed juliusdev closed 2 years ago

juliusdev commented 2 years ago

Hi,

Here, I'm afraid by this report : https://mvnrepository.com/artifact/me.paulschwarz/spring-dotenv/2.5.1

Somes criticals CVE has been detected in the spring framework and fixed in the latest version. Please can you update the project dependencies and release it ?

Cheers, Julien

paulschwarz commented 2 years ago

I've pushed a version upgrade. Please review. Waiting for the release to by synced to the central repository.

paulschwarz commented 2 years ago

It seems the vulnerability report has not changed despite upgrading Spring Framework to the latest version. Any ideas? https://mvnrepository.com/artifact/me.paulschwarz/spring-dotenv/2.5.2

paulschwarz commented 2 years ago

I released 2.5.3 which is available from mavenCentral already, but it takes a while to be reflected in the Maven Repository unfortunately (sometimes a day).

Please check and confirm.

paulschwarz commented 2 years ago

Please upgrade to the latest

https://mvnrepository.com/artifact/me.paulschwarz/spring-dotenv/2.5.3