Skip to content

spring-security-crypto-encryption relies on old Spring version with multiple CVEs #2295

@coheigea

Description

@coheigea

Hi,

If I want to use the Spring functionality to encrypt passwords via the spring-security-crypto-encryption feature, it defaults to using Spring Security 5.3.3 which is from 2020 and has multiple CVEs

https://mvnrepository.com/artifact/org.apache.servicemix.bundles/org.apache.servicemix.bundles.spring-security-core/5.3.3.RELEASE_2

Image

Can it be updated to the latest please?

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions