Skip to content

[SECURITY] - 依赖软件 org.apache.tomcat.embed:tomcat-embed-core:jar:10.1.40 有安全漏洞 bug #5106

@vikeria

Description

@vikeria

Steps to Reproduce

org.apache.tomcat.embed:tomcat-embed-core:jar:10.1.40 有安全漏洞,
软件依赖路径:
org.apache.servicecomb:java-chassis-spring-boot-starter-servlet -> org.springframework.boot:spring-boot-starter-web:jar:3.4.5 -> org.springframework.boot:spring-boot-starter-tomcat:jar:3.4.5 -> org.apache.tomcat.embed:tomcat-embed-core:jar:10.1.40
参考信息:
https://nvd.nist.gov/vuln/detail/CVE-2025-48989
GHSA-gqp3-2cvr-x8m3

Expected Behavior

升级org.springframework.boot:spring-boot-starter-web:jar:3.4.5到3.4.9

Servicecomb Version

3.3.0

Additional Context

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions