[ https://issues.apache.org/jira/browse/VELOCITY-954?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
zhaizeyu resolved VELOCITY-954. ------------------------------- Resolution: Done If the main software has no vulnerability, no handling is required. > spring-velocity-support involve CVE-2022-22965 > ----------------------------------------------- > > Key: VELOCITY-954 > URL: https://issues.apache.org/jira/browse/VELOCITY-954 > Project: Velocity > Issue Type: Bug > Affects Versions: 2.3 > Reporter: zhaizeyu > Priority: Major > > spring-velocity-support 2.3 contains passive dependencies spring-beans 5.3.4 > spring-beans involve vulnerabilities CVE-2022-22965,need to upgrade component > to fix the vulnerability -- This message was sent by Atlassian Jira (v8.20.10#820010) --------------------------------------------------------------------- To unsubscribe, e-mail: dev-unsubscr...@velocity.apache.org For additional commands, e-mail: dev-h...@velocity.apache.org