seata
Chainguard
Status
Impact
The logback-core 1.2.x vulnerability is a transitive dependency required by spring-boot 2.7.x. Remediation requires upstream seata maintainers to migrate from spring-boot 2.7.x to spring-boot 3.x, which requires significant functional changes beyond simple dependency version updates. The fix version logback-core 1.5.19+ requires spring-boot 3.x compatibility.
Status