org.springframework.security/spring-security-web

spring-security-web
mavenframework

Overview

Canonical component data stored by Polaris.

Version

5.0.0.RELEASE

Package Manager

maven

Type

framework

Systems

1

Licenses
Apache-2.0
Direct Dependencies

1

Technology

Not linked

External Signals
deps.dev endoflife.date OSV.dev
Package URL

pkg:maven/org.springframework.security/[email protected]?type=jar

Maintenance

Derived from available component and registry data

Aging
Confidence

Low

Version Age

3173 days

Update Status

Unknown

Recent Activity

Yes

Reasons
Very old versionUnsupported versionUpdate status unknown

Lifecycle

Source: endoflife.date

Unknown
No lifecycle match available
The mapped product was not available from the third-party lifecycle source.
Open endoflife.date

Registry

Source: deps.dev

Available
Ecosystem

maven

Latest Version

7.1.0

Published

11/27/2017

Recent Releases

31

Advisories

5

Open deps.dev

Known Vulnerabilities

Source: OSV.dev

5 found

GHSA-293q-567p-wmwq

Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Affected Versions
>= 6.5.0, before 6.5.116.4.0 - 6.4.136.0.0 - 6.3.10 +2 more
Open advisory

GHSA-c4q5-6c82-3qpw

Spring Security vulnerable to Authorization Bypass of Static Resources in WebFlux Applications

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected Versions
all versions before 5.7.13>= 5.8.0, before 5.8.15>= 6.2.0, before 6.2.7 +3 more
Open advisory

GHSA-gq28-h5vg-8prx

Privilege escalation in spring security

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Versions
>= 5.4.0, before 5.4.4>= 5.3.0, before 5.3.8all versions before 5.2.9
Open advisory

GHSA-hh32-7344-cg2f

Authorization bypass in Spring Security

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Versions
>= 5.5.0, before 5.5.7>= 5.6.0, before 5.6.4all versions before 5.4.11
Open advisory

GHSA-mf92-479x-3373

Spring Security HTTP Headers Are not Written Under Some Conditions

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected Versions
<= 5.7.145.8.0 - 5.8.166.0.0 - 6.3.10 +3 more
Open advisory
Open OSV.dev

Security

Source: OpenSSF Scorecard

Unavailable
No security scorecard available
This component does not have a repository reference for OpenSSF Scorecard lookup.

Dependencies

1 direct dependency

Global view