<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class="">
<div class="">Hello,</div>
<div class=""><br class="">
</div>
<div class="">I have just been notified about a possible serious vulnerability targeting any Java application running on JDK 9.0+ (I would also assume JRE 9.0+ is affected) containing ”Spring framework and derivative framework spring-beans-*.jar”, see:
<a href="https://www.javai.net/post/202203/spring-0day-vulnerability/" class="">https://www.javai.net/post/202203/spring-0day-vulnerability/</a></div>
<div class=""><br class="">
</div>
<div class="">Module idp-core of project java-identity-provider does include a dependency to spring-beans-5.3.17.jar, thus potentially being affected by the vulnerability. Does this need to be handled?</div>
<div class=""><br class="">
</div>
<div class="">Regards,</div>
<div class=""><span id="x-apple-selection:end"></span>Per</div>
<div class=""><br class="webkit-block-placeholder">
</div>
<div class="">
<div style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class="">
<div style="color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px;">
<b class="">Per Engström</b><br class="">
Systemutvecklare / Systems Developer<br class="">
<br class="">
<b class="">SMHI / Swedish Meteorological and Hydrological Institute</b><br class="">
SE - 601 76 NORRKÖPING<br class="">
<a href="http://www.smhi.se" class="">www.smhi.se</a><br class="">
<br class="">
E-post / Email: per.engstrom@smhi.se<br class="">
Tel / Phone: +46 (0)11 495 83 37<br class="">
Besöksadress / Street address: Folkborgsvägen 17</div>
</div>
</div>
<br class="">
</body>
</html>