chore: upgrade org.springframework:spring-expression #8
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Upgrade
org.springframework:spring-expressionfrom4.3.16.RELEASEto5.3.39This pull request upgrades
org.springframework:spring-expressionfrom version4.3.16.RELEASEto5.3.39to address multiple security vulnerabilities and ensure compliance with security best practices. The upgrade has been tested locally to confirm compatibility with existing functionality.Vulnerabilities Addressed
| CVE-2023-20861 | Spring Framework vulnerable to denial of service via specially crafted SpEL expression. Spring Framework vulnerable to denial of service via specially crafted SpEL expression |
| CVE-2023-20863 | Spring Framework vulnerable to denial of service. Spring Framework vulnerable to denial of service |
| CVE-2024-38808 | Spring Framework vulnerable to Denial of Service. Spring Framework vulnerable to Denial of Service |
This upgrade enhances the security and stability of the
org.springframework:spring-expressiondependency.