I would need some help with this security vulnerability
CVE-2019-9628 - We see that grails package uses the OpenSAML -> XMLtooling package which has the following
CVE-2019-9628.
https://mvnrepository.com/artifact/org.opensaml/xmltooling
Is grails affected by this vulnerable or any guidance on remediation?
CVE-2016-1000027 - Is there a way to remove the httpInvoker package that is deprecated. Right now its showing in scan reports from microsoft defender and tagging it as critical, some of our federal customers have concerns, as they have security policy to not install applications with critical vulnerability. We are using grails 6.2.2 and can't move to 7 as its still in MVP, where this has been resolved. Also do you have an ETA when Grails 7 with be GA