Package
apache-activemq-5.19
Component
spring-webmvc
Latest update
5.3
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
The spring-webmvc dependency at version 5.3.39 contains a vulnerability (GHSA-w3c8-7r8f-9jp8) that the advisory claims is fixed in 5.3.42. However, 5.3.42 has not been published publicly: Maven Central has no org.springframework:spring-webmvc:5.3.42 artifact, and the spring-projects/spring-framework repo's 5.3.x tags stop at v5.3.39. Post-5.3.39 fixes are delivered through Spring's commercial support program (Tanzu Spring) and are not available to open-source consumers. Resolution requires either:
Status