From <https://spring.io/security/cve-2024-38816> (...
# questions
m
From https://spring.io/security/cve-2024-38816 (which is the same vulnerability, but with different input)
However, malicious requests are blocked and rejected when any of the following is true:
• the Spring Security HTTP Firewall is in use
• the application runs on Tomcat or Jetty
j
Going forward Grails will more closely follow the Spring Boot and Spring Framework release schedules, since they have significantly shortened the OSS support window. They do offer commercial support via Broadcom. https://endoflife.date/spring-framework https://endoflife.date/spring-boot It is important to begin planning to move to Grails 7 now, which will be released on the latest versions of Spring Boot and Spring Framework. If your app(s) are on Grails 5 or earlier, it may make sense to look at updating to Grails 6.2.1 or 6.2.2 (which will be released soon) as an intermediate step, depending upon your dev resources.
👍 6
👍🏼 1