Package
apache-activemq-fips-5.19
Component
spring-webmvc
Latest update
5.9
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
The spring-webmvc dependency at version 5.3.39 contains a vulnerability (GHSA-r936-gwx5-v52f) that is fixed in Spring Framework 6.2.10. This is a transitive dependency brought in via upstream Apache ActiveMQ 5.19.6 and cannot be directly overridden. Resolution requires:
Status