spring-petclinic / spring-framework-petclinic

A Spring Framework application based on JSP, Spring MVC, Spring Data JPA, Hibernate and JDBC

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Security Vulnerability with H2

muralits opened this issue · comments

CRITICAL Vulnerability found in non-os package type (java) - /app/app.jar:BOOT-INF/lib/h2-1.4.200.jar (CVE-2021-23463 - https://nvd.nist.gov/vuln/detail/CVE-2021-23463)

How to fix this?

We have to upgrade the H2 database version. Do you want to work on this subject?

Fix with #61