Lucene search

K
springBrian ClozelSPRING:8742ADFAF232CA701C5B60203FC92373
HistoryNov 27, 2023 - 12:00 a.m.

CVE-2023-34053, CVE-2023-34055: Spring Framework and Spring Boot vulnerabilities

2023-11-2700:00:00
Brian Clozel
spring.io
175
spring framework
spring boot
update asap
cve-2023-34053
cve-2023-34055

AI Score

7.2

Confidence

Low

EPSS

0.001

Percentile

16.2%

Updates

  • [11-27] Blog posts updated to refer to the CVE reports published

The Spring Framework 6.0.14 release shipped on November 16th includes a fix for CVE-2023-34053.

The Spring Boot 2.7.18 release shipped on November 23th includes fixes for CVE-2023-34055.

Users are encouraged to update as soon as possible.

AI Score

7.2

Confidence

Low

EPSS

0.001

Percentile

16.2%