Commons IO dependency affected by CVE-2024-47554
ThomasVitale opened this issue · 1 comments
ThomasVitale commented
The spring-shell-core module uses commons-io:commons-io:2.11.0 which is affected by CVE-2024-47554.
The solution is to upgrade to version 2.14+
corneil commented
Bumped to 2.18.0