You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Yes. We run security scans and dependabot to keep dependencies up to date.
Currently, Security scans do not show any vulnerabilities in Shiro.
There are no current vulnerabilities listed in "Spring Boot's dependent software" that we are aware of.
I do not believe Shiro has is actually using vulnerability in the above CVE, so it doesn't really apply here.
Also, looks like Quartz scheduler is abandoned.
I am going to close this issue. Will leave your PR open under discussion in Slack
Search before asking
Question
org.quartz.jobs.ee.jms.SendQueueMessageJob.execute
would lead the code injection vulnerability. quartz-scheduler/quartz#943The text was updated successfully, but these errors were encountered: