Spring

 Hello Is SpringBoot 2.7.19 available? Or do you know when this update will be finished? Kind regards Tino Hildebrandt

Tino Hildebrandt's profile image
Tino Hildebrandt posted Feb 12, 2024 01:33 PM

 

Todd Robbins's profile image
Broadcom Employee Todd Robbins

Hello Tino,

 

There will be a commercial patch release for Spring Boot (2.7.19) available later this month (February) for customers with VMware Spring Runtime entitlement. These commercial patches will be available on the Spring Commercial Repository: https://repo.spring.vmware.com

 

For access information on this repository, please see the KB article: How to access Spring Commercial Subscription Repository.

Tino Hildebrandt's profile image
Tino Hildebrandt

Hello Todd

 

Thank you for the answer.

 

Best regards

Tino

Neven Cvetkovic's profile image
Broadcom Employee Neven Cvetkovic

The above KB article results in Invalid Page:

https://community.pivotal.io/s/article/How-to-access-Spring-Commercial-Subcription-repoistory

 

image 

Who has rights to see this KB?

 

Thanks,

Neven

Neven Cvetkovic's profile image
Broadcom Employee Neven Cvetkovic

Ah it was a typo in the link, the correct link is:

https://community.pivotal.io/s/article/How-to-access-Spring-Commercial-Subscription-repository

 

Todd Robbins's profile image
Broadcom Employee Todd Robbins

My apologies. Yes, that is correct link. Thank you Neven.

Prasad Bodapati's profile image
Prasad Bodapati

Hi Todd,

 

We also have support contract with VM ware for springboot.

 

I want to find whether CVV 10 vulnerabilities in spring-web-5.3.32 are fixed in new 2.7.19 of spring boot?

 

We have not subscribed to with the private repository I will contact with our internal teams to do that.

Neven Cvetkovic's profile image
Broadcom Employee Neven Cvetkovic

Hey Prasad,

 

Please file a technical ticket so we can follow up and help you setup your private repository.

 

We have just released a new Spring Boot 2.7.20.1 release that fixes some new CVEs, see details here:

https://spring.io/blog/2024/03/14/spring-framework-6-1-5-6-0-18-and-5-3-33-available-now-including-fixes-for

 

Cheers!

Neven