spring-security
Safeguard articles tagged "spring-security" — guides, analysis, and best practices for software supply chain and application security.
16 articles
org.springframework:spring-web: Known CVEs and How to Stay Patched
A security-focused look at org.springframework:spring-web, including the Spring4Shell RCE, how spring-web relates to spring-webmvc, and how to keep the dependency safe.
spring-security-crypto: What It Does and How to Use It Safely
The spring-security-crypto module gives Spring apps password hashing, symmetric encryption, and key generation without pulling in the full security framework. Here is how to use each piece correctly.
CVE-2023-34042: How the Spring Security XSD Permission Flaw Works
CVE-2023-34042 is a world-writable file permission issue in Spring Security's config JAR. Here is what actually breaks, who is affected, and how to remediate it.
CVE-2024-22234: The Spring Security Access Control Bypass Explained
CVE-2024-22234 is a broken access control flaw in Spring Security where isFullyAuthenticated returns true for a null authentication. Here is how it works and how to fix it.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.