Spring Beans 0day Vulnerability

Engström Per per.engstrom at smhi.se
Wed Mar 30 09:11:52 UTC 2022


Hello,

I have just been notified about a possible serious vulnerability targeting any Java application running on JDK 9.0+ (I would also assume JRE 9.0+ is affected) containing ”Spring framework and derivative framework spring-beans-*.jar”, see: https://www.javai.net/post/202203/spring-0day-vulnerability/

Module idp-core of project java-identity-provider does include a dependency to spring-beans-5.3.17.jar, thus potentially being affected by the vulnerability. Does this need to be handled?

Regards,
Per

Per Engström
Systemutvecklare / Systems Developer

SMHI / Swedish Meteorological and Hydrological Institute
SE - 601 76 NORRKÖPING
www.smhi.se<http://www.smhi.se>

E-post / Email: per.engstrom at smhi.se
Tel / Phone: +46 (0)11 495 83 37
Besöksadress / Street address: Folkborgsvägen 17

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20220330/e96b2bf7/attachment.htm>


More information about the users mailing list