Skip to content

Vaadin 24.0.11

Compare
Choose a tag to compare
@vaadin-bot vaadin-bot released this 25 Jul 05:46
· 10 commits to 24.0 since this release
a5431eb

This is a maintenance release for Vaadin 24.0. See 24.0.0 release notes for details and resources.

Note

To fix cve-2023-34035, Spring Security 6.0.5 has been introduced a breaking change. Vaadin 24.0.11 is compatible with the latest Springboot containing the breaking change.

Changelogs

Official add-ons and plugins:

  • Spring add-on (24.0.12)
  • CDI add-on (15.0.1)
  • Maven plugin (24.0.11)
  • Gradle plugin (24.0.11)
  • Quarkus plugin (2.0.1)

known vulnerability

TestBench brings the dependency pkg:maven/com.google.guava/[email protected], that has the vulnerability described in CVE-2020-8908 and CVE-2023-2976, the problematic method has been deprecated in guava and it is not used in Vaadin.