We are using AWS Inspector to scan our application...
# questions
u
We are using AWS Inspector to scan our application image. As part of the scan, there are few Vulnerability reported by AWS Inspector. We are using the Grails 6.2.1 version. Is the below CVE's Valid and impacted? CVE-2024-38816 CVE-2024-38819 CVE-2024-38820 CVE-2024-38827 CVE-2024-38828 CVE-2025-22228 CVE-2025-24813 CVE-2021-28170 CVE-2023-22102
j
I can’t answer these specific CVEs but there are known CVEs with the Spring framework. Unfortunately Broadcom changed their support policy so unless you buy enterprise support the patches are not available. This is one of the reasons 7.0.0 is so important.