Spring Security is a powerful and highly customizable authentication and access-control framework. It provides protection against attacks like session fixation, clickjacking, cross site request forgery, etc
| License | Apache 2.0 |
|---|---|
| Categories | Security Frameworks |
| Tags | securityspringframework |
| Organization | spring.io |
| HomePage | http://spring.io/spring-security 🔍 Inspect URL |
| Date | Jan 25, 2018 |
| Files | pom (8 KB) jar (367 KB) View All |
| Repositories | CentralAlfrescoCloudFlight PluginsImageJ PublicMulesoftSonatypeSpring Releases |
| Ranking | #206 in MvnRepository (See Top Artifacts) #1 in Security Frameworks |
| Used By | 2,873 artifacts |
| Vulnerabilities | Direct vulnerabilities: CVE-2024-38827 CVE-2024-22257 CVE-2022-22978 View 2 more ... Vulnerabilities from dependencies: CVE-2025-22233 CVE-2024-38820 CVE-2024-38808 View 15 more ... |
Compile Dependencies (12)
| Category/License | Group / Artifact | Version | Updates | |
|---|---|---|---|---|
| AOP Public | aopalliance » aopalliance | 1.0 | ✔ | |
| Logging Apache 2.0 | commons-logging » commons-logging (optional) | 1.2 | 1.3.5 | |
| Annotation Lib CDDLGPL 2.0 | javax.annotation » jsr250-api (optional) | 1.0 | 1.3.2 | |
| Cache Impl Apache 2.0 | net.sf.ehcache » ehcache (optional) | 2.9.0 | 3.11.1 | |
| AOP EPL 2.0 | org.aspectj » aspectjrt (optional) | 1.8.4 | 1.9.25 | |
| AOP Apache 2.0 | org.springframework » spring-aop | 4.3.14.RELEASE | 7.0.0 | |
| Dep Injection Apache 2.0 | org.springframework » spring-beans2 vulnerabilities | 4.3.14.RELEASE | 7.0.0 | |
| Dep Injection Apache 2.0 | org.springframework » spring-context3 vulnerabilities | 4.3.14.RELEASE | 7.0.0 | |
| Core Utils Apache 2.0 | org.springframework » spring-core5 vulnerabilities | 4.3.14.RELEASE | 7.0.0 | |
| Expression Lang Apache 2.0 | org.springframework » spring-expression4 vulnerabilities | 4.3.14.RELEASE | 7.0.0 | |
| JDBC Extension Apache 2.0 | org.springframework » spring-jdbc (optional) | 4.3.14.RELEASE | 7.0.0 | |
| Transactions Apache 2.0 | org.springframework » spring-tx (optional) | 4.3.14.RELEASE | 7.0.0 |
Test Dependencies (14)
| Category/License | Group / Artifact | Version | Updates | |
|---|---|---|---|---|
| Logging EPL 1.0LGPL 2.1 | ch.qos.logback » logback-classic2 vulnerabilities | 1.1.2 | 1.5.21 | |
| Collections Apache 2.0 | commons-collections » commons-collections | 3.2.2 | 4.5.0 | |
| Testing EPL 2.0 | junit » junit1 vulnerability | 4.12 | 6.0.1 | |
| Assertion Apache 2.0 | org.assertj » assertj-core | 2.2.0 | 3.27.6 | |
| Embedded SQL DB | org.hsqldb » hsqldb1 vulnerability | 2.3.2 | 2.7.4 | |
| Mocking MIT | org.mockito » mockito-core | 1.10.19 | 5.20.0 | |
| Mocking Apache 2.0 | org.powermock » powermock-api-mockito | 1.6.2 | 2.0.9 | |
Apache 2.0 | org.powermock » powermock-api-support | 1.6.2 | 2.0.9 | |
| Mocking Apache 2.0 | org.powermock » powermock-core | 1.6.2 | 2.0.9 | |
| Mocking Apache 2.0 | org.powermock » powermock-module-junit4 | 1.6.2 | 2.0.9 | |
Apache 2.0 | org.powermock » powermock-module-junit4-common | 1.6.2 | 2.0.9 | |
Apache 2.0 | org.powermock » powermock-reflect | 1.6.2 | 2.0.9 | |
| Logging Bridge Apache 2.0 | org.slf4j » jcl-over-slf4j | 1.7.7 | 2.0.17 | |
| Testing Apache 2.0 | org.springframework » spring-test | 4.3.14.RELEASE | 7.0.0 |
Licenses
| License | URL |
|---|---|
| The Apache Software License, Version 2.0 | http://www.apache.org/licenses/LICENSE-2.0.txt |
Developers
| Name | Dev Id | Roles | Organization | |
|---|---|---|---|---|
| Rob Winch | rwinch<at>gopivotal.com | rwinch |