Skip to content

Conversation

@labkey-willm
Copy link
Contributor

Rationale

We don't use @EnableMethodSecurity, so we are not impacted by CVE-2025-41249

Related Pull Requests

Changes

@labkey-jeckels
Copy link
Contributor

Even when we're not affected, we typically upgrade to the patched version of the library in our current ESR (25.7 at the moment) instead of suppressing it. This means we don't have to prove that we're not vulnerable when a client's scan sees that we reference a library with a CVE.

@labkey-willm labkey-willm deleted the 25.9_fb_spring_cve_suppress branch September 18, 2025 00:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants