Package
kayenta-2025.4
Component
spring-security-web
Latest update
6.8
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
The affected X.509 principal-extractor fix is only available in a later major release line of the security framework, which requires a coordinated upgrade of the core framework beyond the version this component is compatible with. No backport exists for the supported release line, so remediation is pending an upstream release that adopts the newer framework baseline.
Status