Spring Framework is vulnerable to a security issue: https://nvd.nist.gov/vuln/detail/CVE-2018-1257 It's fixed in newer branches, but we still have an older unsupported branch, so a fix would need to be backported. There's another issue that I believe doesn't affect us: https://nvd.nist.gov/vuln/detail/CVE-2018-1258 Mageia 6 is also affected.
Whiteboard: (none) => MGA6TOO
Whiteboard: MGA6TOO => MGA7TOO, MGA6TOO
CC: (none) => mageiaWhiteboard: MGA7TOO, MGA6TOO => MGA7TOO
CVE: (none) => CVE-2020-5421URL: (none) => https://nvd.nist.gov/vuln/detail/CVE-2020-5421CC: (none) => zombie_ryushu
Another issue fixed in newer branches, but would need to be backported: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-5421 https://nvd.nist.gov/vuln/detail/CVE-2020-5421 Package was (mercifully) dropped from Cauldron.
Whiteboard: MGA7TOO => (none)Summary: springframework new security issue CVE-2018-1257 => springframework new security issues CVE-2018-1257 and CVE-2020-5421Version: Cauldron => 7URL: https://nvd.nist.gov/vuln/detail/CVE-2020-5421 => (none)
Debian-LTS has issued an advisory on April 23: https://www.debian.org/lts/security/2021/dla-2635 The issues are fixed upstream in 4.3.20.
Severity: normal => criticalSummary: springframework new security issues CVE-2018-1257 and CVE-2020-5421 => springframework new security issues CVE-2018-1257, CVE-2018-1270, CVE-2018-11039, CVE-2018-11040, CVE-2018-15756, CVE-2020-5421
https://blog.mageia.org/en/2021/06/08/mageia-7-will-reach-end-of-support-on-30th-of-june-the-king-is-dead-long-live-the-king/
Resolution: (none) => OLDStatus: NEW => RESOLVED