Skip to content

Upgrading the versions of Netty, Jetty and Spring6#6023

Open
guptas6est wants to merge 2 commits intoeclipse-ee4j:3.0from
Nordix:fix/netty_jetty_spring6_3.0
Open

Upgrading the versions of Netty, Jetty and Spring6#6023
guptas6est wants to merge 2 commits intoeclipse-ee4j:3.0from
Nordix:fix/netty_jetty_spring6_3.0

Conversation

@guptas6est
Copy link
Copy Markdown

Why:
To remediate the following vulnerabilities in 3.0 branch:

Netty

CVE-2025-55163
CVE-2025-58056
CVE-2025-58057

Jetty

CVE-2025-5115

Spring 6

CVE-2024-38820
CVE-2025-22233
CVE-2025-41234
CVE-2025-41249

What:
Upgraded the dependency versions

Netty - 4.1.122.Final -> 4.1.128.Final
Jetty - 11.0.25 -> 11.0.26
Jetty 9 - 9.4.57.v20241219 -> 9.4.58.v20250814
Spring 6 - 6.0.23 -> 6.2.11

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant