CVEs Coming from Transitive A12 Dependencies

We have just started a new A12 Project based on the Fullstack Project Template (2024.06-ext1). Running a security scan on that code revealed ~20 CVEs in transitive A12/Spring dependencies.
For example CVE-2023-39017 in quartz-2.3.2.jar and CVE-2023-44487 in jetty-server-9.4.49.v20220914.jar

Is there any overview where I can quickly check if those haven been already addressed by A12 and where I can derive our required actions on those (wait for the next A12 Update, exclude the dependency, etc.)?

Hello @eduard-polar-knoll,

We leverage Atlas for security scanning; the result is being tracked at the wiki, I sent you via Webex chat since you’re mgm internal

They’d probably not fully meet your needs, but I hope it would help.

Cheers,
Loi