This issue stands as a place holder to track the progress of resolving the issue described at FAQ for CVE-2022-22965.
As part of normal security practice, we do not disclose security issues until they are fully resolved in our products so as to mitigate the risk to our customers. In this case the broader security concern was raised publicly by a third party, so broad stroke information about the issue is already available.
We cannot disclose particular details of the issue, and the FAQ for CVE-2022-22965 remains the single source of truth. Once this issue is resolved, we will update this issue to point to the security disclosure issue with additional detail.
UPDATE
We’ve released these new versions with an upgraded version of Tomcat which also serves to mitigate this issue:
- is cloned from
-
CONFSERVER-78586 Tracking Resolution of Issue Described in FAQ for CVE-2022-22965
- Closed
- is related to
-
JRASERVER-73773 Upgrade Tomcat to version 8.5.78 - CVE-2022-22965 (Spring Framework RCE)
- Closed
- relates to
-
JPOSERVER-4353 Upgrade an external library to fix the vulnerability CVE-2022-22965
- Closed
- is blocked by
-
VULN-732672 Loading...