Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

Conversation

@00felix-app
Copy link

@00felix-app 00felix-app bot commented Aug 6, 2025

Upgrade org.springframework:spring-expression from 4.3.16.RELEASE to 5.3.39

This pull request upgrades org.springframework:spring-expression from version 4.3.16.RELEASE to 5.3.39 to address multiple security vulnerabilities and ensure compliance with security best practices. The upgrade has been tested locally to confirm compatibility with existing functionality.
Vulnerabilities Addressed

Vulnerability Description
CVE-2022-22950 Allocation of Resources Without Limits or Throttling in Spring Framework. Allocation of Resources Without Limits or Throttling in Spring Framework

| CVE-2023-20861 | Spring Framework vulnerable to denial of service via specially crafted SpEL expression. Spring Framework vulnerable to denial of service via specially crafted SpEL expression |

| CVE-2023-20863 | Spring Framework vulnerable to denial of service. Spring Framework vulnerable to denial of service |

| CVE-2024-38808 | Spring Framework vulnerable to Denial of Service. Spring Framework vulnerable to Denial of Service |

This upgrade enhances the security and stability of the org.springframework:spring-expression dependency.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants

Morty Proxy This is a proxified and sanitized view of the page, visit original site.