Spring Security is a powerful and highly customizable authentication and access-control framework. It provides protection against attacks like session fixation, clickjacking, cross site request forgery, etc
| License | Apache 2.0 |
|---|---|
| Categories | Security Frameworks |
| Tags | securityspringframework |
| Organization | spring.io |
| HomePage | https://spring.io/spring-security 🔍 Inspect URL |
| Date | Jul 08, 2024 |
| Files | pom (6 KB) jar (438 KB) View All |
| Repositories | Spring MilestonesSpringFrameworkSpring Plugins Snap |
| Ranking | #206 in MvnRepository (See Top Artifacts) #1 in Security Frameworks |
| Used By | 2,874 artifacts |
| Vulnerabilities | Direct vulnerabilities: CVE-2024-38827 CVE-2024-22257 CVE-2022-22976 Vulnerabilities from dependencies: CVE-2025-41249 CVE-2025-22233 CVE-2024-38820 View 15 more ... |
Note: this artifact is located at Spring Milestones repository (https://repo.spring.io/milestone/)
Compile Dependencies (12)
| Category/License | Group / Artifact | Version | Updates | |
|---|---|---|---|---|
| JSON Lib Apache 2.0 | com.fasterxml.jackson.core » jackson-databind (optional) 4 vulnerabilities | 2.12.0-rc1 | 3.0.2 | |
| Concurrency Apache 2.0 | io.projectreactor » reactor-core (optional) | 3.4.0 | 3.8.0 | |
| Annotation Lib CDDLGPL 2.0 | javax.annotation » jsr250-api (optional) | 1.0 | 1.3.2 | |
| Cache Impl Apache 2.0 | net.sf.ehcache » ehcache (optional) | 2.10.6 | 3.11.1 | |
| AOP EPL 2.0 | org.aspectj » aspectjrt (optional) | 1.9.6 | 1.9.25 | |
| AOP Apache 2.0 | org.springframework » spring-aop | 5.3.0 | 7.0.0 | |
| Dep Injection Apache 2.0 | org.springframework » spring-beans2 vulnerabilities | 5.3.0 | 7.0.0 | |
| Dep Injection Apache 2.0 | org.springframework » spring-context3 vulnerabilities | 5.3.0 | 7.0.0 | |
| Core Utils Apache 2.0 | org.springframework » spring-core3 vulnerabilities | 5.3.0 | 7.0.0 | |
| Expression Lang Apache 2.0 | org.springframework » spring-expression4 vulnerabilities | 5.3.0 | 7.0.0 | |
| JDBC Extension Apache 2.0 | org.springframework » spring-jdbc (optional) | 5.3.0 | 7.0.0 | |
| Transactions Apache 2.0 | org.springframework » spring-tx (optional) | 5.3.0 | 7.0.0 |
Test Dependencies (15)
| Category/License | Group / Artifact | Version | Updates | |
|---|---|---|---|---|
| Collections Apache 2.0 | commons-collections » commons-collections | 3.2.2 | 4.5.0 | |
| Testing Apache 2.0 | io.projectreactor » reactor-test | 3.4.0 | 3.8.0 | |
| Testing EPL 2.0 | junit » junit1 vulnerability | 4.12 | 6.0.1 | |
| Assertion Apache 2.0 | org.assertj » assertj-core | 3.18.0 | 3.27.6 | |
| Embedded SQL DB | org.hsqldb » hsqldb1 vulnerability | 2.5.1 | 2.7.4 | |
| Mocking MIT | org.mockito » mockito-core | 3.3.3 | 5.20.0 | |
| Mocking Apache 2.0 | org.powermock » powermock-api-mockito2 | 2.0.7 | 2.0.9 | |
Apache 2.0 | org.powermock » powermock-api-support | 2.0.7 | 2.0.9 | |
| Mocking Apache 2.0 | org.powermock » powermock-core | 2.0.7 | 2.0.9 | |
| Mocking Apache 2.0 | org.powermock » powermock-module-junit4 | 2.0.7 | 2.0.9 | |
Apache 2.0 | org.powermock » powermock-module-junit4-common | 2.0.7 | 2.0.9 | |
Apache 2.0 | org.powermock » powermock-reflect | 2.0.7 | 2.0.9 | |
| Testing Apache 2.0 | org.skyscreamer » jsonassert | 1.5.0 | 1.5.3 | |
| Logging Bridge Apache 2.0 | org.slf4j » jcl-over-slf4j | 1.7.30 | 2.0.17 | |
| Testing Apache 2.0 | org.springframework » spring-test | 5.3.0 | 7.0.0 |
Licenses
| License | URL |
|---|---|
| The Apache Software License, Version 2.0 | https://www.apache.org/licenses/LICENSE-2.0.txt |
Developers
| Name | Dev Id | Roles | Organization | |
|---|---|---|---|---|
| Rob Winch | rwinch<at>pivotal.io | rwinch | ||
| Joe Grandja | jgrandja<at>pivotal.io | jgrandja |