Hi

I raised a question in springcloud git with regards to vulnerability CVE-2016-9878 (https://pivotal.io/security/cve-2016-9878), and they recommended to raise the problem here (https://github.com/spring-cloud/spring-cloud-commons/issues/174)

As springcloud depends on spring-security-crypto, looks like its also vulnerable to CVE-2016-9878

Is there any plan to release a version where this is solved?

Thanks

Comment From: eleftherias

This has been fixed in gh-4375.