From fb7a2df73f01c58bcbd6ede3055fca2fbad0ba79 Mon Sep 17 00:00:00 2001 From: qlonglong Date: Tue, 21 Oct 2025 20:58:29 +0800 Subject: [PATCH] upgrade org.apache.tomcat.embed:tomcat-embed-core to 9.0.108 Due to JDK version constraints, Spring Boot cannot be upgraded further. Therefore, tomcat-embed-core can only be upgraded to 9.0.108 to address the CVE-2025-48989 vulnerability. --- dependencies/default/pom.xml | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) diff --git a/dependencies/default/pom.xml b/dependencies/default/pom.xml index c9132cc26d..46bb111570 100644 --- a/dependencies/default/pom.xml +++ b/dependencies/default/pom.xml @@ -101,6 +101,7 @@ 4.5.21 2.24.0 2.16.3 + 9.0.108 ${basedir}/../.. @@ -774,6 +775,22 @@ ${java-websocket.version} + + org.apache.tomcat.embed + tomcat-embed-core + ${tomcat.version} + + + org.apache.tomcat.embed + tomcat-embed-el + ${tomcat.version} + + + org.apache.tomcat.embed + tomcat-embed-websocket + ${tomcat.version} + + org.apache.servicecomb java-chassis-bom