[ 
https://issues.apache.org/jira/browse/AMQ-9334?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17783176#comment-17783176
 ] 

Hemakumar commented on AMQ-9334:
--------------------------------

[~jbertram] The reason for asking this question is, We are using Active MQ 
Classic 5.18.2. This contains a critical vulnerability (CVE-2016-1000027) on 
org.springframework:spring-web:5.3.30 and it suggest to migrate to 
org.springframework:spring-web:6.0.0 version. I was just wondering would this 
upgrade be updated in any of the upcoming minor version 5.18.x or should we 
wait for ActiveMQ 6.0 to be released. Thanks.

> Upgrade to Spring 6.0.13
> ------------------------
>
>                 Key: AMQ-9334
>                 URL: https://issues.apache.org/jira/browse/AMQ-9334
>             Project: ActiveMQ
>          Issue Type: Dependency upgrade
>            Reporter: Jean-Baptiste Onofré
>            Assignee: Jean-Baptiste Onofré
>            Priority: Major
>             Fix For: 6.0.0
>
>          Time Spent: 20m
>  Remaining Estimate: 0h
>




--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to