Root has patched CVE-2023-20861 in the io.root.org.springframework:spring-expression package for Root:Maven. Multiple fixed versions available.
{ "distro": "maven", "severity": "MEDIUM", "source": "Root", "distro_version": "" }
1.0
"root.io.4"
[ "5.3.20-root.io.4" ]
"https://api.root.io/external/osv/ROOT-APP-MAVEN-CVE-2023-20861.json"
"5.3.20"
true
""
[ "5.3.20-aikido.4" ]
"5.3.20-aikido.4"