Skip to content

UAA 3.3.0.4 - Security Release (CVE-2016-5007)

Choose a tag to compare

@sreetummidi sreetummidi released this 15 Aug 18:25
· 5554 commits to master since this release

This is a security release which addresses CVE-2016-5007 Spring Security / MVC Path Matching Inconsistency

This following dependencies have been updated

  • Spring Security 4.1.1
  • Spring Framework 4.3.1
  • Spring Security Oauth 2.0.10
  • Spring Security LDAP 2.1.0
  • Spring Security SAML 1.0.2
  • Apache Tomcat 8.0.36
  • Apache Tomcat jdbc-pool 7.0.70