Skip to content

PXF 2.0 using Spring-Boot ecosystem component dependencies - Security vulnerability #1805

@NadeemRajput-sys

Description

@NadeemRajput-sys

@tuhaihe Regarding PXF2.0, seems like using Spring Boot 2.5.12 ecosystem framework:

Is PXF built using Spring Boot 2.5.12 ecosystem components?

If yes, can this be patched to latest version (OR) removed, to make it supported by PXF avoiding vulnerabilities ?

I can see multiple Sprin-boot components:

spring-boot-gradle-plugin-2.5.12.jar
spring-boot-starter-web-2.5.12.jar
spring-boot-starter-tomcat-2.5.12.jar
spring-boot-actuator-2.5.12.jar
spring-boot-autoconfigure-2.5.12.jar

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions