CVE-2022-22965
For information about CVE-2022-22965 as it applies to Atlassian's products see https://confluence.atlassian.com/kb/faq-for-cve-2022-22965-1115149136.html
The Spring Spring Framework version used in Bitbucket Server/Data Center should be updated to 5.3.19.
Note that while CVE-2022-22965 is addressed in 5.3.18, some of the restrictions break non-bundled plugins. This is fixed in Spring 5.3.19 as described here: https://github.com/spring-projects/spring-framework/issues/28269
- was cloned as
-
BSERV-13371 Update Spring Framework dependency to 5.3.20
- Closed
- relates to
-
BBSDEV-26264 Loading...
(1 mentioned in, 1 relates to)