Package
kayenta-2025.4
Component
spring-webmvc
Latest update
Fixed version
2025.4.3-r7
5.9
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Fixed version
2025.4.3-r7Status
Impact
Spring Framework 6.0.x has no patch for this vulnerability (firstPatchedVersion: null for >=6.0.0, <=6.0.x).
The package's spring-framework version is constrained by spring-boot 3.0.13 starters / 3.1.2 core (transitively via io.spinnaker.orca:orca-bom 8.64.0). Spring-boot 3.0/3.1 natively pair with spring-framework 6.0.x; 6.1+ requires spring-boot 3.2+ and 6.2+ requires 3.3+.
A unified spring-framework 6.2.17 bump was attempted. Build passed; the daemon test failed at Tomcat startup due to spring-boot/spring-framework API skew (jackson DatatypeFeature NoClassDefFoundError, then ObjectMapper bean autowiring conflict in KayentaConfiguration). Resolution requires upstream Spinnaker to bump spring-boot to 3.3+.
Status
Fixed version
2025.4.3-r6Status
Impact
We are unable to bump this spring dependency as it is tighlty dependent on the spring framework version being used. We need to wait for upstream to bump the spring framework version in order to remediate this CVE.
Status