Skip to content

Commit 88774b8

Browse files
upgrade org.apache.tomcat.embed:tomcat-embed-core to 9.0.108 (#4986)
Due to JDK version constraints, Spring Boot cannot be upgraded further. Therefore, tomcat-embed-core can only be upgraded to 9.0.108 to address the CVE-2025-48989 vulnerability.
1 parent 6c85f1b commit 88774b8

File tree

1 file changed

+17
-0
lines changed

1 file changed

+17
-0
lines changed

dependencies/default/pom.xml

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -101,6 +101,7 @@
101101
<vertx.version>4.5.21</vertx.version>
102102
<zipkin.version>2.24.0</zipkin.version>
103103
<zipkin-reporter.version>2.16.3</zipkin-reporter.version>
104+
<tomcat.version>9.0.108</tomcat.version>
104105
<!-- Base dir of main -->
105106
<main.basedir>${basedir}/../..</main.basedir>
106107
</properties>
@@ -774,6 +775,22 @@
774775
<version>${java-websocket.version}</version>
775776
</dependency>
776777

778+
<dependency>
779+
<groupId>org.apache.tomcat.embed</groupId>
780+
<artifactId>tomcat-embed-core</artifactId>
781+
<version>${tomcat.version}</version>
782+
</dependency>
783+
<dependency>
784+
<groupId>org.apache.tomcat.embed</groupId>
785+
<artifactId>tomcat-embed-el</artifactId>
786+
<version>${tomcat.version}</version>
787+
</dependency>
788+
<dependency>
789+
<groupId>org.apache.tomcat.embed</groupId>
790+
<artifactId>tomcat-embed-websocket</artifactId>
791+
<version>${tomcat.version}</version>
792+
</dependency>
793+
777794
<dependency>
778795
<groupId>org.apache.servicecomb</groupId>
779796
<artifactId>java-chassis-bom</artifactId>

0 commit comments

Comments
 (0)