Override the Spring Vulnerable version in the cas 6.6.6
26 views
Skip to first unread message
Raj Vivid
unread,
Apr 4, 2023, 12:33:32 AM4/4/23
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to CAS Community
HI Team,
While using the cas 6.6.6, we found that it internally uses the vulnerable Spring framework version ( https://mvnrepository.com/artifact/org.springframework.boot/spring-boot/2.7.3) while building the war, Is there any way we can override the usage of Spring version so that we can avoid the possible vulnerability?
Also is the later versions going to use a new Spring version?