Uploaded image for project: '[Read Only] - Hippo Site Toolkit 2'
  1. [Read Only] - Hippo Site Toolkit 2
  2. HSTTWO-2747

Upgrade Spring dependency to 3.2.5.RELEASE

    XMLWordPrintable

Details

    • Improvement
    • Status: Closed
    • Normal
    • Resolution: Fixed
    • 2.26.08
    • 2.28.00-alpha-1, 2.28.00
    • None
    • Sprint 69

    Description

      A vulnerability was found in the Spring framework: http://seclists.org/fulldisclosure/2013/Nov/31

      This has no direct impact on our stack since both affected modules (Spring MVC and OXM) are not used/packaged by vanilla HST2, but as the impact of upgrading to the latest v3.2.4 of Spring is probably minimal we would like implementations of the HST to use these modules with the latest, secure release of Spring.

      More info:

      Attachments

        Activity

          People

            jsheriff Junaidh Kadhar Sheriff
            abogaart Arthur Bogaart
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: