fix(deps): update dependency org.springframework:spring-context to v6.2.7 [security] - #26
Closed
nanjingfm wants to merge 1 commit into
Closed
fix(deps): update dependency org.springframework:spring-context to v6.2.7 [security]#26nanjingfm wants to merge 1 commit into
nanjingfm wants to merge 1 commit into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
6.2.1->6.2.7Spring Framework DataBinder Case Sensitive Match Exception
CVE-2025-22233 / GHSA-4wp7-92pw-q264
More information
Details
CVE-2024-38820 ensured Locale-independent, lowercase conversion for both the configured disallowedFields patterns and for request parameter names. However, there are still cases where it is possible to bypass the disallowedFields checks.
Affected Spring Products and Versions
Spring Framework:
6.2.0 - 6.2.6
6.1.0 - 6.1.19
6.0.0 - 6.0.27
5.3.0 - 5.3.42
Older, unsupported versions are also affected
Mitigation
Users of affected versions should upgrade to the corresponding fixed version.
No further mitigation steps are necessary.
Generally, we recommend using a dedicated model object with properties only for data binding, or using constructor binding since constructor arguments explicitly declare what to bind together with turning off setter binding through the declarativeBinding flag. See the Model Design section in the reference documentation.
For setting binding, prefer the use of allowedFields (an explicit list) over disallowedFields.
Credit
This issue was responsibly reported by the TERASOLUNA Framework Development Team from NTT DATA Group Corporation.
Severity
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:NReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Release Notes
spring-projects/spring-framework (org.springframework:spring-context)
v6.2.7⭐ New Features
AbstractJackson2HttpMessageConverter#getObjectMappersForTypenullness #34811@RequestBodyparameters lose generic type information when creating HTTP service beans #34793🐞 Bug Fixes
PropertySourcesPlaceholderConfigurerplaceholder resolution fails in several scenarios #34861BeanOverrideHandlerdiscovered in@Nestedtest case with superclass from different class or in interface implemented multiple times #34844NamedParameterUtilsonly expands reused collection parameter once #34768PathMatchingResourcePatternResolverwrongly assumes thattarget/classesalways exists #34764📔 Documentation
CompositePropertySourcebehavior forEnumerablePropertySourcecontract #34886@Nullableannotation forservletContextparameter ofConfigurableWebEnvironment.initPropertySourcesare contradictory #34845@EnableAsyncneeds to be redeclared for each ApplicationContext #34843🔨 Dependency Upgrades
❤️ Contributors
Thank you to all the contributors who worked on this release:
@Artur-, @blake-bauman, @iifawzi, @kilink, @quaff, @whlit, and @zzoe2346
v6.2.6⭐ New Features
@ContextHierarchy#34723exchangeForRequiredValuevariant toRestClient#34692CoroutinesUtils#34682🐞 Bug Fixes
SseEmitter.onCompletion()behavior between Spring 6.2.3 and 6.2.5 #34762PropertyBatchUpdateException: causes of nestedPropertyAccessExceptions not shown in output #34691@Configurationclasses can no longer beabstractwithout@Beanmethods #34663@MockitoBeanwith custom@Qualifieris not injected into@Configurationclass #34646📔 Documentation
ignoreDependencyInterface()inAbstractAutowireCapableBeanFactory#34747ListableBeanFactory#getBeansOfType#34629❤️ Contributors
Thank you to all the contributors who worked on this release:
@acktsap, @dmitrysulman, @iggzq, @izeye, @ngocnhan-tran1996, @obourgain, and @tobias-haenel
v6.2.5⭐ New Features
spring-core-testoptional #34612-parameterswhenAspectJAdviceParameterNameDiscovererfails against ambiguity #34609FormHttpMessageConvertershould throwHttpMessageNotReadableExceptionwhen the http form data is invalid #34594🐞 Bug Fixes
📔 Documentation
MvcUriComponentsBuilderjavadocs inaccurately reflects usage of forwarded headers #34615StringUtils#uriDecodeJavadoc #34590🔨 Dependency Upgrades
❤️ Contributors
Thank you to all the contributors who worked on this release:
@Helmsdown, @dmitrysulman, and @ngocnhan-tran1996
v6.2.4⭐ New Features
ContentResultMatchersDslmatchers for supertypes of the checked type #34542JarURLConnectionresource leak inAbstractFileResolvingResource.exists()#34528rowsExpectedproperty ofSqlQueryfor removal #34526RuntimeHintsto anAotContextLoader#34513DefaultRestClientBuilder#34439BeanFactory/ObjectProviderto select the only one default candidate among non-default candidates #34432🐞 Bug Fixes
MockCookie.parse()fails to parse custom attribute with a value #34575BeanNotOfRequiredTypeExceptionif@Beanfactory method returnsnull#34543@someHash] under bean name 'blabla': there is already object [@sameHash] bound" #34427NullPointerExceptionthrown whenConfigurationClassEnhancercreates CGLIB proxy #34423📔 Documentation
@sincetag for formField() and formFields in MockHttpServletRequestDsl #34448TestExecutionListenercallbacks #34422🔨 Dependency Upgrades
❤️ Contributors
Thank you to all the contributors who worked on this release:
@chenggangpro, @dark2momo, @dmitrysulman, @izeye, @ngocnhan-tran1996, @pankratz76, @quaff, @ryanprayogo, and @vpavic
v6.2.3⭐ New Features
@MockitoSpyBeanat the type level on test classes #34408TestExecutionListenerimplementations as constants #34404ConversionServiceto convert POJO to array for SpEL varargs invocations #34371🐞 Bug Fixes
@Primarysemantics #34374Mapthat implementsIterableno longer works #34332BeanOverrideHandlerdiscovered in@Nestedtest class hierarchy when upgrading to Spring 6.2.2 #34324AnnotationBeanNameGeneratorissues warning about explicitly aliasedvalueattribute #34317ConfigurationClassEnhancershould explicitly set customClassLoaderon CGLIBEnhancer(aligned withCglibAopProxy) #34274📔 Documentation
@Lookupmethods #34367StandardWebSocketSession#34304SpringProperties.getFlag()#34295SimpleCommandLinePropertySource#34282TestExecutionListenerimplementations #34265🔨 Dependency Upgrades
❤️ Contributors
Thank you to all the contributors who worked on this release:
@JoshuaChen, @Puppy4C, @anaconda875, @brandenclark, @canattofilipe, @dobrosi, @izeye, @jazdw, @khoutz182, @kwondh5217, @pirocraft, @quaff, @remeio, and @tarekmues
v6.2.2⭐ New Features
BeanOverrideHandler#34260@FunctionalInterfacedeclaration fromBeanOverrideProcessor#34259@MockitoBeanat the type level on test classes #33925🐞 Bug Fixes
@TestBeanfactory method resolution is incorrect within class hierarchy #34204AsyncListener#onErrordoes not return until dispatch completes #34192DataBinderthrowsIndexOutOfBoundsExceptionwhen indexed parameter uses nonconsecutive indices #34145DataBinderthrowsStringIndexOutOfBoundsExceptionfor indexed property without nested property path #34121MethodHandlefunction reference accepting only varargs #34109DataBinderthrowsStringIndexOutOfBoundsExceptionfor map property without nested property path #34043EvalTag#33945📔 Documentation
@EventListener#34057🔨 Dependency Upgrades
❤️ Contributors
Thank you to all the contributors who worked on this release:
@Mattias-Sehlstedt, @Spanching, @brendenehlers, @izeye, @luozongle01, @micopiira, @ngocnhan-tran1996, @quaff, @rPraml, @remeio, and @scordio
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Renovate Bot.