Bug 23976 - springframework-data-commons new security issue CVE-2018-1273
Summary: springframework-data-commons new security issue CVE-2018-1273
Status: RESOLVED OLD
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Java Stack Maintainers
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2018-12-08 19:00 CET by David Walser
Modified: 2021-07-01 18:18 CEST (History)
1 user (show)

See Also:
Source RPM: springframework-data-commons-1.8.4-8.mga7.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2018-12-08 19:00:25 CET
Spring Data Commons is vulnerable to a security issue:
https://nvd.nist.gov/vuln/detail/CVE-2018-1273

It's fixed in newer branches, but we still have an older unsupported branch, so a fix would need to be backported.

There's another issue that I believe doesn't affect us:
https://nvd.nist.gov/vuln/detail/CVE-2018-1259

Mageia 6 is also affected.
David Walser 2018-12-08 19:00:31 CET

Whiteboard: (none) => MGA6TOO

David Walser 2019-06-23 19:32:07 CEST

Whiteboard: MGA6TOO => MGA7TOO, MGA6TOO

Nicolas Lécureuil 2020-05-22 14:08:34 CEST

Whiteboard: MGA7TOO, MGA6TOO => MGA7TOO
CC: (none) => mageia

Comment 1 Nicolas Lécureuil 2020-12-26 23:29:04 CET
not in cauldron anymore

Whiteboard: MGA7TOO => (none)
Version: Cauldron => 7

Comment 2 David Walser 2021-07-01 18:18:52 CEST
https://blog.mageia.org/en/2021/06/08/mageia-7-will-reach-end-of-support-on-30th-of-june-the-king-is-dead-long-live-the-king/

Status: NEW => RESOLVED
Resolution: (none) => OLD


Note You need to log in before you can comment on or make changes to this bug.