Package
kayenta-fips-2025.4
Component
spring-security-web
Latest update
9.1
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Status
Impact
Kayenta currently depends on a vulnerable version of spring-security-web (6.0.8). Upgrading to 6.0.13 is not possible, as that version is restricted to Enterprise Support. However, upgrading to the lowest available open-source patched version (6.2.7) results in test failures. Consequently, the upstream project will need to migrate from 6.0.x to 6.2.x to remediate this vulnerability.
Status