geoserver-2.27
Chainguard
Status
Impact
This vulnerability affects spring-core 5.3.39. The fix is available in Spring Framework 6.2.11. GeoServer 2.27.x currently uses Spring Framework 5.3.x which has reached end of open-source support with no public fix available for the 5.3.x line. GeoServer main branch has updated to Spring Framework 6.x (commit fd0cd28d8323e38dffbaaa91f784a9b8057d4a5d) which contains the fix. Resolution requires upstream GeoServer maintainers to backport Spring Framework 6.x support to the 2.27.x stable branch. Reference: https://github.com/geoserver/geoserver/commit/fd0cd28d8323e38dffbaaa91f784a9b8057d4a5d
Status