-
Task
-
Resolution: Fixed
-
L3 - Default
-
None
-
None
-
None
The core engine has a spring-beans dependency which is used for bootstrapping the engine via camunda.cfg.xml. It currently uses Spring 3, which is out of support for a long time already and has several known vulnerabilities. While the engine can be safely used with Spring 4 and Spring 5 already, by default we pull in an unsafe dependency which then e.g. shows up in vulenerability report tools.
This is the controller panel for Smart Panels app
- is related to
-
CAM-11422 Extract the managed Spring artifacts' version from the parent
- Closed