Package
apache-activemq-5.19
Component
spring-webmvc
Latest update
7.5
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
The spring-webmvc dependency at version 5.3.39 contains a vulnerability (GHSA-g5vr-rgqm-vf78) that is fixed in Spring Framework 6.1.14. This is a transitive dependency brought in via upstream Apache ActiveMQ 5.19.6 and cannot be directly overridden. Resolution requires:
Status