Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Snakeyaml 1.33 vulnerability #406

Closed
khaeghar opened this issue Sep 25, 2023 · 1 comment
Closed

Snakeyaml 1.33 vulnerability #406

khaeghar opened this issue Sep 25, 2023 · 1 comment
Labels
status/need-triage Team needs to triage and take a first look

Comments

@khaeghar
Copy link

Hi,

I was wondering if there's any plan on upgrading the snakeyaml version from 1.33 to 2.x, since 1.33 contains a vulnerability.

Kind regards!

@github-actions github-actions bot added the status/need-triage Team needs to triage and take a first look label Sep 25, 2023
@onobc
Copy link
Contributor

onobc commented Sep 25, 2023

Hi @khaeghar

We have no current plans to bump to 2.x as the changes would ripple through Spring Boot. Once Boot updates, we likely will too. In the meantime, the CVE does not affect dataflow as we have mitigated the flaws. Please see https://github.com/spring-cloud/spring-cloud-dataflow/security/advisories/GHSA-578p-phm8-hcj9

@onobc onobc closed this as completed Sep 25, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
status/need-triage Team needs to triage and take a first look
Projects
None yet
Development

No branches or pull requests

2 participants