-
Notifications
You must be signed in to change notification settings - Fork 168
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Hibernate vulnerability #1771
Comments
There were a few attempts to raise the version without success:
We should get back to the topic when the current Spring Boot version 1.5.22.RELEASE is raised to 2.x Until then the library spring-data-jpa-entity-graph (1.11.03) looks like a cornerstone correlating with Hibernate Core |
What is the confusion, @blootsvoets ? |
Ehm, no confusion, just sad that Spring Boot 1.5 and the latest Hibernate versions don't work together nicely. |
Agreed. For the 3.0 line we'll be bringing everything up to date: JDK 14+ etc. |
Linking this to #2244 |
Hibernate has a SQL injection vulnerability in version 5.4.21, which is resolved in version 5.4.24:
https://app.snyk.io/vuln/SNYK-JAVA-ORGHIBERNATE-1041788
The text was updated successfully, but these errors were encountered: