Second Spring CVE announced
Cantor, Scott
cantor.2 at osu.edu
Wed Apr 13 15:43:13 UTC 2022
To head off questions,
The Spring team announced another CVE today [1] in conjunction with another Spring Framework update, both of which were more or less expected because they had announced an early release of this new version. The new release appears to be primarily shoring up the earlier fix and making it more robust against misconfiguration.
We still do not believe that the IdP is vulnerable to the original issue, but we still can't prove that.
Our plan is to proceed with the 4.2 release tomorrow (it may not be out tomorrow, we have to release lots of libraries too). We *may* do a 4.1.7 patch as well, fairly likely just as a courtesy, though that will be the final 4.1 patch if we do so regardless of future developments.
-- Scott
[1] https://spring.io/blog/2022/04/13/spring-framework-data-binding-rules-vulnerability-cve-2022-22968
More information about the announce
mailing list