Package
apache-activemq-fips-5.19
Component
spring-webmvc
Latest update
7.5
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
The spring-webmvc dependency at version 5.3.39 contains a vulnerability (GHSA-cx7f-g6mp-7hqm) that is fixed in Spring Framework 6.1.13. This is a transitive dependency brought in via upstream Apache ActiveMQ 5.19.6 and cannot be directly overridden. Resolution requires:
Status