Skip to content

Critical Vulnerabilities in Spring components picked up by Trivy scan #2410

@Nic-Ed

Description

@Nic-Ed

Expected behavior

No vulnerabilities (especially high or critical severity ones) should be found on a Trivy scan

Actual behavior

Critical vulnerabilities are detected in Spring framework and other components. I'm aware of the closed issue here: #2298 and the fact the vulnerability only applies with JDK9+. This isn't really a satisfactory solution for us . Can you advise if there has been or will be a fix for this issue so that there are no critical or high severity vulnerabilities detected after scanning WebAPI installed from the latest release?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions