1.1.6
1 years ago
17 days ago
Known vulnerabilities in the org.springframework.ai:spring-ai-openai package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
org.springframework.ai:spring-ai-openai is an OpenAI models support Affected versions of this package are vulnerable to Missing Authorization via the default configuration of the Spring AI chat memory component. An attacker can access data from other users when Note: The upgrade fix for this vulnerability is a breaking change, due to the default How to fix Missing Authorization? Upgrade | [,1.0.7)[1.1.0-M1,1.1.6) |