3 ms·
It looks like they are mixing it up with CVE-2022-22963 related to spring cloud[1] from a few days ago and one of the members of the Spring project is reporting
by Copenjin 5y ago
It looks like they are mixing it up with CVE-2022-22963 related to spring cloud[1] from a few days ago and one of the members of the Spring project is reporting that there is no vulnerability associated with the deserialization fix everyone (the chinese OP, the eng posts) is referring to.
https://twitter.com/Ax_Sharma/status/1509103877978824707 https://twitter.com/Ax_Sharma/status/1509103877978824707
[1] https://spring.io/blog/2022/03/29/cve-report-published-for-spring-cloud-function https://spring.io/blog/2022/03/29/cve-report-published-for-s...
[2] https://github.com/spring-projects/spring-framework/pull/28075 https://github.com/spring-projects/spring-framework/pull/280...