legacy-knowledge-base
公開されました Jun. 30, 2025

Is Liferay vulnerable to CVE-2024-38819: SpringFramework (spring-core-5.3.39)?

投稿者

Marcos da Silva Xavier

knowledge-article-header-disclaimer-how-to

knowledge-article-header-disclaimer

legacy-article

learn-legacy-article-disclaimer-text

Issue

Environment

  • Liferay DXP 7.3 +

Resolution

  • A fix was made available in version 5.3.41. However spring only gives the updated version for the commercial customer. In our 7.3.x upstream and beyond, we removed the usage of spring-webmvc as it is unused to avoid this issue.

    In case you are using an older version, please open a ticket requesting a hotfix from Liferay Support in order to remove the spring jars files.

 

 

did-this-article-resolve-your-issue

legacy-knowledge-base