Spring Framework 5.3.x < 5.3.26 / 6.0.x < 6.0.7 Security Bypass (CVE-2023-20860)

Cantor, Scott cantor.2 at osu.edu
Thu Jul 6 12:12:38 UTC 2023


All known issues in libraries shipped in our releases are triaged and covered on the Security Advisories page, which would help were the Confluence cloud not down at the moment. Suffice to say it's there and we are not impacted.

If the vulnerability weren't listed there, then it would be fair game to report it to the security reporting address for assessment.

-- Scott




More information about the users mailing list