openvsx
openvsx copied to clipboard
[Vulnerability] spring-webmvc 5.3.1 in docker image openvsx-server (CVE-2022-22965)
I downloaded and scanned openvsx-server docker image version 72706d1, and found that it has/uses/references spring-webmvc 5.3.1 (CVE-2022-22965)
could you confirm if this is actually used within the image? And if yes, are there any plans to update it to >= 5.3.18?
