See how pivotal software compares to other vendors in security performance
Spring Tools for Eclipse renders Spring Boot starter wizard dependency tooltips in a native embedded browser (SWT Browser) with JavaScript enabled. Using untrusted and compromised Initializr endpoints for the Spring Boot starter wizard can result in arbitrary script execution inside the embedded browser when a developer hovers a dependency checkbox in the New Spring Starter Project wizard. Impact is limited to in-IDE UI spoofing and outbound network beaconing rather than full code execution. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier
End of life: 7/31/2027, Latest version: 4.1.0
Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead to a directory traversal attack. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: affected from 4.1.0 through 4.1.9 (inclusive); upgrade to 4.1.10 or greater (Enterprise Support Only). Spring Cloud Config 4.2.x: affected from 4.2.0 through 4.2.6 (inclusive); upgrade to 4.2.7 or greater (Enterprise Support Only). Spring Cloud Config 4.3.x: affected from 4.3.0 through 4.3.2 (inclusive); upgrade to 4.3.3 or greater. Spring Cloud Config 5.0.x: affected from 5.0.0 through 5.0.2 (inclusive); upgrade to 5.0.3 or greater.
In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vulnerable, it must: be a servlet-based web application; have no Spring Security configuration of its own and rely on the default web security filter chain; depend on spring-boot-actuator-autoconfigure; not depend on spring-boot-health. If any of the above does not apply, the application is not vulnerable.
Affected: Spring Boot 4.0.0–4.0.5; upgrade to 4.0.6 or later per vendor advisory.
Latest version: 4.3.5
End of life: 7/31/2027, Latest version: 7.0.8
End of life: 12/31/2026, Latest version: 4.0.7
End of life: 7/31/2026, Latest version: 4.2.9
End of life: 6/30/2026, Latest version: 3.5.16
End of life: 1/30/2026, Latest version: 4.1.8
End of life: 6/30/2026, Latest version: 6.2.19
End of life: 6/30/2026, Latest version: 6.2.19
End of life: 12/31/2025, Latest version: 3.4.13
End of life: 12/31/2025, Latest version: 3.4.13
End of life: 4/15/2025, Latest version: 4.0.9
End of life: 4/15/2025, Latest version: 4.0.9
End of life: 6/30/2025, Latest version: 3.3.13
End of life: 6/30/2025, Latest version: 3.3.13
End of life: 9/17/2024, Latest version: 3.13.7
End of life: 9/17/2024, Latest version: 3.13.7
End of life: 12/31/2024, Latest version: 3.2.12
End of life: 12/31/2024, Latest version: 3.2.12
End of life: 6/30/2025, Latest version: 6.1.21
End of life: 6/30/2025, Latest version: 6.1.21
End of life: 2/21/2024, Latest version: 3.12.14
End of life: 2/21/2024, Latest version: 3.12.14
End of life: 6/30/2024, Latest version: 3.1.12
End of life: 6/30/2024, Latest version: 3.1.12
End of life: 6/30/2024, Latest version: 6.0.23
End of life: 6/30/2024, Latest version: 6.0.23