Package
geoserver-2.27
Component
spring-security-web
Latest update
6.1
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
The affected security library is at 5.8.16, the final public release of its 5.8.x line. The vendor lists 5.8.26 as the fix for that branch but distributes it only to commercial support subscribers, and no 5.8.x release above 5.8.16 is published to Maven Central. The open-source fixes are 6.5.11 and 7.0.6, which require a framework major upgrade and the Jakarta EE namespace, while this release line runs the 5.3.x framework. Upstream adopted the fixed major in its 3.0 line rather than backporting, so the fix cannot be applied within this version stream.
Status