The Spring4Shell vulnerability allows remote code execution (RCE) for applications. A related vulnerability was subsequently discovered that is of a similar nature but involves different Spring components.
Gradle Enterprise < 2022.2 includes Spring platform libraries that contain the vulnerabilities. However, its usage of the libraries does not meet the preconditions for exposing the vulnerabilities.
To avoid creating false positives when scanning the the Gradle Enterprise distribution for known vulnerabilities, version 2022.1.1 updates Spring components to version 5.3.18 in order to address CVE-2022-22965, while version 2022.2 updates Spring components to version 5.3.19 in order to address CVE-2022-22968.