nshestiuk opened a new pull request, #1522:
URL: https://github.com/apache/activemq/pull/1522

   Fix for 
https://spring.io/blog/2024/09/12/spring-framework-5-3-40-and-6-0-24-available-now
   
   **Impact:** An attacker can craft malicious HTTP requests and obtain any 
file on the file system that is also accessible to the process in which the 
Spring application is running.
   
   > **Affected Spring Products and Versions**
   > Spring Framework:
   >
   >    5.3.0 - 5.3.40
   >    6.0.0 - 6.0.24
   >    6.1.0 - 6.1.13
   >    Older, unsupported versions are also affected
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]
For further information, visit: https://activemq.apache.org/contact


Reply via email to