Skip to content

Update Spring Framework to 5.3.31 to fix security vulnerability#6

Open
oli99sc wants to merge 2 commits intoScout24:masterfrom
oli99sc:update-spring-version
Open

Update Spring Framework to 5.3.31 to fix security vulnerability#6
oli99sc wants to merge 2 commits intoScout24:masterfrom
oli99sc:update-spring-version

Conversation

@oli99sc
Copy link
Copy Markdown

@oli99sc oli99sc commented Mar 25, 2025

Description

This PR addresses the security vulnerability identified in SEC-16479 by updating the Spring Framework version from 4.0.5.RELEASE to 5.3.31.

Changes

  • Updated Spring Framework version from 4.0.5.RELEASE to 5.3.31 to address the unsafe Java deserialization vulnerability (GHSA-4wrc-f8pq-fpqp)
  • Added Dependabot configuration to enable automated dependency updates in the future

Testing

The project should be thoroughly tested after this update to ensure that everything still works with the new Spring version, as this is a major version upgrade (4.x to 5.x).

References

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant