Skip to content

upgrade spring-security version to 5.4.6 #502

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 3 commits into from
Apr 15, 2021
Merged

upgrade spring-security version to 5.4.6 #502

merged 3 commits into from
Apr 15, 2021

Conversation

liga-oz
Copy link
Contributor

@liga-oz liga-oz commented Apr 13, 2021

spring-security 5.4.5 has a vulnerability spring-projects/spring-security#4001 that is fixed in the 5.4.6

@liga-oz liga-oz requested a review from nenaraab April 13, 2021 12:31
Copy link
Contributor

@nenaraab nenaraab left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM 👍

@artem-smotrakov
Copy link

This vulnerability doesn't seem to be fixed in 5.4.6. This pull requests address it but it is not merged yet

spring-projects/spring-security#8082

@nenaraab
Copy link
Contributor

Hi @artem-smotrakov thanks for the link!
My favorite would be to wait for a patched spring-boot version to solve the transient dependencies of our spring starter projects.
@liga-oz would you mind to open an issue to track that?

@nenaraab nenaraab merged commit 02bbf7d into master Apr 15, 2021
@nenaraab nenaraab deleted the fix-spring-vuln branch April 15, 2021 07:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Unresolved CSRF token BREACH Attack org.springframework.security -> spring-security-web
3 participants