Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade Spring Framework version to fix Spring Vulnerability #42

Open
rehammuzzamil opened this issue Jul 29, 2022 · 3 comments
Open

Upgrade Spring Framework version to fix Spring Vulnerability #42

rehammuzzamil opened this issue Jul 29, 2022 · 3 comments
Assignees

Comments

@rehammuzzamil
Copy link

https://spring.io/blog/2022/04/13/spring-framework-data-binding-rules-vulnerability-cve-2022-22968

Update Spring Version to 5.3.19

cc: @dubdabasoduba @f-odhiambo

@rehammuzzamil rehammuzzamil self-assigned this Jul 29, 2022
@rehammuzzamil
Copy link
Author

Observations:
I see the HAPI team has worked on a fix under release 1.1.4.HAPI FHIR 6.0.1 (Tanuki) . It was released on Released: 2022-05-25.

image (3)

In my opinion,it would definitely be a part of the quarterly release by the HAPI team, which is expected to be on 2022-08-18 by the name of HAPI FHIR 6.1.0 (TBD).
For more context, please refer to https://hapifhir.io/hapi-fhir/docs/introduction/changelog.html

Please let me know your thoughts on this @dubdabasoduba .
cc : @f-odhiambo @ageryck

@dubdabasoduba
Copy link
Member

dubdabasoduba commented Aug 12, 2022

I think this makes sense. Do we have PRs fixing the same on our extension & keycloak repo?

@rehammuzzamil
Copy link
Author

I will share PRs when done.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants