Skip to content

Conversation

@00felix-app
Copy link

@00felix-app 00felix-app bot commented Aug 7, 2025

Upgrade org.springframework.security:spring-security-web from 4.2.12.RELEASE to 5.7.13

This pull request upgrades org.springframework.security:spring-security-web from version 4.2.12.RELEASE to 5.7.13 to address multiple security vulnerabilities and ensure compliance with security best practices. The upgrade has been tested locally to confirm compatibility with existing functionality.
Vulnerabilities Addressed

Vulnerability Description
CVE-2021-22112 Privilege escalation in spring security. Privilege escalation in spring security

| CVE-2022-22978 | Authorization bypass in Spring Security. Authorization bypass in Spring Security |

| CVE-2024-38821 | Spring Security vulnerable to Authorization Bypass of Static Resources in WebFlux Applications. Spring Security vulnerable to Authorization Bypass of Static Resources in WebFlux Applications |

This upgrade enhances the security and stability of the org.springframework.security:spring-security-web dependency.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant