Skip to content

Backport fix for CWE-862 to 5.4 #10878

@strowk

Description

@strowk

Expected Behavior

I would like if minor version 5.4 was available, which does not fail security analysis tools. Currently CWE-862 seems to not be fixed earlier than 5.6, but unfortunately we are unable to migrate to Spring Boot 5.5 at the moment.

These ones seem to be related:
#9931
#9795

Current Behavior

./gradlew dependencyCheckAnalyze fails with following error:

spring-security-core-5.4.9.jar (pkg:maven/org.springframework.security/spring-security-core@5.4.9, cpe:2.3:a:pivotal_sof
tware:spring_security:5.4.9:*:*:*:*:*:*:*) : CWE-862: Missing Authorization

Context

We are not able to build our project anymore because of this security problem.

Metadata

Metadata

Assignees

Labels

status: blockedAn issue that's blocked on an external project change

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions