We would be interested in a response to whether or not any Esri products are vulnerable to the recently announced Spring Framework RCE CVE (https://spring.io/blog/2022/03/31/spring-framework-rce-early-announcement) and if so what mitigations / updates can be put in place to remediate the vulnerability.
So far, no information yet. The Security Team is still looking into the issue, Keep checking this Post for updates.
Signed in members can post, follow updates, and more. New here? Register a free account.
Find useful guides, FAQs, and documents to help you navigate and make the most of Esri Community.