Information on source package libspring-java

Available versions

ReleaseVersion
stretch4.3.5-1
stretch (security)4.3.5-1+deb9u1
buster4.3.22-4
bullseye4.3.30-1
sid4.3.30-1

Open issues

BugstretchbusterbullseyesidDescription
CVE-2020-5421vulnerable (no DSA, ignored)vulnerable (no DSA)fixedfixedIn Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5. ...
CVE-2018-1272vulnerable (no DSA, ignored)fixedfixedfixedSpring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior t ...
CVE-2018-1257vulnerable (no DSA, ignored)fixedfixedfixedSpring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior ...
CVE-2018-1199vulnerable (no DSA, ignored)fixedfixedfixedSpring Security (Spring Security 4.1.x before 4.1.5, 4.2.x before 4.2. ...

Resolved issues

BugDescription
CVE-2021-22118In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x ...
CVE-2020-5398In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x pri ...
CVE-2020-5397Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF ...
CVE-2018-15756Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, version ...
CVE-2018-11040Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3 ...
CVE-2018-11039Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior ...
CVE-2018-1275Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior t ...
CVE-2018-1271Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior t ...
CVE-2018-1270Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior t ...
CVE-2016-1000027Pivotal Spring Framework 4.1.4 suffers from a potential remote code ex ...
CVE-2016-9878An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2 ...
CVE-2016-5007Both Spring Security 3.2.x, 4.0.x, 4.1.0 and the Spring Framework 3.2. ...
CVE-2015-5211Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4 ...
CVE-2015-3192Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not pro ...
CVE-2015-0201The Java SockJS client in Pivotal Spring Framework 4.1.x before 4.1.5 ...
CVE-2014-3625Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 th ...
CVE-2014-3578Directory traversal vulnerability in Pivotal Spring Framework 3.x befo ...
CVE-2014-1904Cross-site scripting (XSS) vulnerability in web/servlet/tags/form/Form ...
CVE-2014-0225When processing user provided XML documents, the Spring Framework 4.0. ...
CVE-2014-0097The ActiveDirectoryLdapAuthenticator in Spring Security 3.2.0 to 3.2.1 ...
CVE-2014-0054The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Frame ...
CVE-2013-7315The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4 ...
CVE-2013-6430The JavaScriptUtils.javaScriptEscape method in web/util/JavaScriptUtil ...
CVE-2013-6429The SourceHttpMessageConverter in Spring MVC in Spring Framework befor ...
CVE-2013-4152The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, ...

Security announcements

DSA / DLADescription
DLA-2635-1libspring-java - security update
DLA-1853-1libspring-java - security update
DSA-2890-1libspring-java - security update
DSA-2857-1libspring-java - several
DSA-2842-1libspring-java - several

Search for package or bug name: Reporting problems