PT-2022-37449 · Spring+1 · Spring Framework+2

Published

2022-04-21

·

Updated

2022-04-21

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions tomcat (affected versions not specified)
Description The issue is related to security hardening and the removal of the log4j dependency, which is not used by the tomcat package. Additionally, it involves deprecating the getResources() function to always return null, addressing Spring Framework vulnerabilities.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

SUSE-SU-2022:1294-1

Affected Products

Spring Framework
Log4J
Apache Tomcat