Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Hibernate vulnerability #1771

Open
blootsvoets opened this issue Feb 4, 2021 · 5 comments
Open

Hibernate vulnerability #1771

blootsvoets opened this issue Feb 4, 2021 · 5 comments

Comments

@blootsvoets
Copy link
Contributor

Hibernate has a SQL injection vulnerability in version 5.4.21, which is resolved in version 5.4.24:
https://app.snyk.io/vuln/SNYK-JAVA-ORGHIBERNATE-1041788

@alex-odysseus
Copy link
Contributor

There were a few attempts to raise the version without success:

We should get back to the topic when the current Spring Boot version 1.5.22.RELEASE is raised to 2.x

Until then the library spring-data-jpa-entity-graph (1.11.03) looks like a cornerstone correlating with Hibernate Core

@chrisknoll
Copy link
Collaborator

What is the confusion, @blootsvoets ?

@blootsvoets
Copy link
Contributor Author

Ehm, no confusion, just sad that Spring Boot 1.5 and the latest Hibernate versions don't work together nicely.

@chrisknoll
Copy link
Collaborator

Agreed. For the 3.0 line we'll be bringing everything up to date: JDK 14+ etc.

@anthonysena
Copy link
Collaborator

Linking this to #2244

@anthonysena anthonysena moved this from Under Review to Review Complete in Atlas/WebAPI Issue Triage Apr 18, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
No open projects
Status: Review Complete
Development

No branches or pull requests

4 participants