Package
kayenta-2025.4
Component
spring-webmvc
Latest update
Fixed version
2025.4.3-r7
7.5
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Fixed version
2025.4.3-r7Status
Impact
Spring Framework 6.0.x has no patch for this vulnerability (firstPatchedVersion: null for >=6.0.0, <=6.0.x).
The package's spring-framework version is constrained by spring-boot 3.0.13 starters / 3.1.2 core (transitively via io.spinnaker.orca:orca-bom 8.64.0). Spring-boot 3.0/3.1 natively pair with spring-framework 6.0.x; 6.1+ requires spring-boot 3.2+ and 6.2+ requires 3.3+.
A unified spring-framework 6.2.17 bump was attempted. Build passed; the daemon test failed at Tomcat startup due to spring-boot/spring-framework API skew (jackson DatatypeFeature NoClassDefFoundError, then ObjectMapper bean autowiring conflict in KayentaConfiguration). Resolution requires upstream Spinnaker to bump spring-boot to 3.3+.
Status
Fixed version
2025.4.3-r6Status
Impact
This Spring Boot component is already at the highest available open-source compatible versions for the Spring Boot 2.7.x release line. The next major open-source update available is Spring Framework v6.0.0, which introduces breaking changes due to its dependency on Spring Boot 3.x and removal of legacy support layers. [v2-migration]
Status