CVE-2019-3778: Spring Security OAuth 2.3.5, 2.2.4, 2.1.4, 2.0.17 Released

Releases | Joe Grandja | February 21, 2019 | ...

We have released Spring Security OAuth 2.3.5, 2.2.4, 2.1.4 and 2.0.17 to address CVE-2019-3778: Open Redirector in spring-security-oauth2. Please review the information in the CVE report and upgrade immediately.

For additional changes included in each release, please refer to:

NOTE: For users of Spring Boot 1.5.x and Spring IO Platform Cairo, it is highly recommended to override the spring-security-oauth version to the latest version containing the fix for the CVE. Please see the Mitigation section in the CVE report for…

What's new with Spring Initializr

Engineering | Madhura Bhave | February 20, 2019 | ...

The quickest way to generate Spring Boot projects is through start.spring.io. The site provides a curated list of dependencies that you can add to your application based on the selected Spring Boot version. You can also choose the language, build system and JVM version for the project. Over the years, the popularity of start.spring.io as the tool for generating Spring projects has grown exponentially and millions of projects are generated every year using the site.

For the past few months, we’ve been working on a complete overhaul of the project generation API. To better understand the…Old Structure

Spring Tips: Season 5 Recap

Engineering | Josh Long | February 20, 2019 | ...

Hi Spring fans! Can you believe it? We're at the end of yet another season - our fifth! - of Spring Tips! I wasn't sure at first (when we started down this journey a few years ago) that these videos would take off or become popular but it seems the Spring community's curiosity knows no bounds!

I try in every season to look at new technology (RSocket and R2DBC, eh, spring to mind..), and to introduce variations on themes (we looked at three projects that extend Spring Cloud to native IaaS-platforms this season!), and to introduce potentially niche but often appreciated topics (this season we…

This Week in Spring - February 19, 2019

Engineering | Josh Long | February 19, 2019 | ...

Hi Spring fans! Welcome to another installment of This Week in Spring! In the US, Monday was a public holiday so today, Tuesday, feels a bit like Monday and i was happily going through the Monday motions and then I got a reminder that I had to write this week's installment! Ooops! Thank goodness for technology.

I'm at San Francisco International Airport about to board a fight for the Washington DC edition of the SpringOne Tour. Are you going to be in Washington DC? Reach out and say hi! My direct messages on Twitter are correct, too

Then, it's off to Kansas City, KS/MO for, among other things, an appearance at the Kansas City JUG this…

A Bootiful Podcast: an Interview with Spring Contributor and "Learning Spring Boot 2.0" author Greg Turnquist

Engineering | Josh Long | February 15, 2019 | ...

It was a lot of fun to talk to Greg Turnquist, one of the more industrious and variously applied members of the Spring family, about how he found his way to the Spring team and community, Python, his new book, Spring team legends like Keith Donald and Brian Dussault, and so much more.

Spring Boot 2.1.3 available now

Releases | Stéphane Nicoll | February 15, 2019 | ...

On behalf of the team and everyone who has contributed, I'm happy to announce that Spring Boot 2.1.3 has been released and is is now available from repo.spring.io and Maven Central.

This release includes over 70 fixes, improvements and dependency upgrades. Thanks to all those who have contributed with issue reports and pull requests.

If you are still using Spring Boot 2.0.x, an upgrade to Spring Boot 2.1.x is strongly encouraged. Following the announcement that Spring Framework 5.0.x will reach its EOL in March, Spring Boot 2.0.x will follow suit with a final release in the 2.0.x line planned for late March. As previously announced, Spring Boot 1.5.x will…

Introducing java-cfenv: A new library for accessing Cloud Foundry Services

Releases | Mark Pollack | February 15, 2019 | ...

Introduction

The Spring Cloud Connectors library has been with us since the launch event of Cloud Foundry itself back in 2011. One of the main goals of the connector library and Cloud Foundry’s Java buildpack was to “reduce the initial investment when you want to get started with Cloud Foundry”. The connector library creates the Spring bean definitions required to connect to backing services, like databases, using information contained in the VCAP_SERVICES environment variable. The buildpack then replaces these bean definitions you had in your application with those created by the connector…

Spring Tips: Apache Geode

Engineering | Josh Long | February 13, 2019 | ...

Hi Spring fans! In this installment of Spring Tips we look at Gemfire... err.. Apache Geode, the fantastic distributed data grid you've probably never heard of, BUT YOU SHOULD, that integrates nicely with the Spring Data for Apache Geode project.

speaker: Josh Long

Get the Spring newsletter

Stay connected with the Spring newsletter

Subscribe

Get ahead

VMware offers training and certification to turbo-charge your progress.

Learn more

Get support

Tanzu Spring offers support and binaries for OpenJDK™, Spring, and Apache Tomcat® in one simple subscription.

Learn more

Upcoming events

Check out all the upcoming events in the Spring community.

View all