Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

截止到20240904目前CVE漏洞列表,希望修复下对应版本 #3535

Closed
liuxin638507 opened this issue Sep 4, 2024 · 2 comments
Closed

Comments

@liuxin638507
Copy link

liuxin638507 commented Sep 4, 2024

Please answer some questions before submitting your issue. Thanks!
目前使用v2.4.1版本,扫描发现一些漏洞,详情列表如图:
image
and

hit:["spring version less than 5.3.38"]
path:/app.jar(BOOT-INF/lib/spring-core-5.3.31.jar)

Which version of XXL-JOB do you using?

v2.4.1

Expected behavior

希望更新下对应CEV漏洞

Actual behavior

Steps to reproduce the behavior

Other information

@xuxueli
Copy link
Owner

xuxueli commented Nov 10, 2024

你好,上述漏洞基本来自于 springboot 2.x。如有诉求可自行升级 springboot 3.x 解决。
项目计划 v2.5.0 升级 springboot3.x 进行修复

@xuxueli
Copy link
Owner

xuxueli commented Nov 10, 2024

合并至 #3425 跟进。
计划 v.2.5.0升级 springboot3 进行修复。

@xuxueli xuxueli closed this as completed Nov 10, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants