Red Hat support for Spring Boot 2.7 is the last planned feature release for version 2
Red Hat offers community support for Spring Boot 3 and future releases.
Red Hat support for Spring Boot
Spring Boot lets you create stand-alone Spring-based applications and (Micro)services. Spring Boot provides ways to implement common (Micro)service patterns, such as externalized configuration, health check, circuit breaker, failover.
browse_doc
Release Notes for Spring Boot 2.7Release Information
Component Details OverviewRelease Information
Dekorate Guide for Spring Boot DevelopersDeveloping applications
latest_security
| severity | advisory_cve | synopsis | date |
|---|---|---|---|
| severity Moderate | advisory_cveCVE-2023-5379 | synopsis A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JBoss EAP is marked in an error state by mod_cluster in httpd, causing JBoss EAP to close the TCP connection without returning an AJP response. This happens because mod_proxy_cluster marks the JBoss EAP instance as an error worker when the TCP connection is closed from the backend after sending the AJP request without receiving an AJP response, and stops forwarding. This issue could allow a malicious user could to repeatedly send requests that exceed the max-header-size, causing a Denial of Service (DoS). | date |
| severity Moderate | advisory_cveCVE-2022-41854 | synopsis Those using Snakeyaml to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack overflow. This effect may support a denial of service attack. | date |
| severity Low | advisory_cveCVE-2020-1698 | synopsis A flaw was found in keycloak. A logged exception in the HttpMethod class may leak the password given as parameter. The highest threat from this vulnerability is to data confidentiality. | date |
| severity Moderate | advisory_cveCVE-2019-10219 | synopsis A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack. | date |
| severity Low | advisory_cveCVE-2019-10184 | synopsis undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api. | date |
top_resources
Knowledgebase
Access articles and solutions to find answers to your questions.
Supported configurations
See your Red Hat-provided production or development support for supported configurations.
Troubleshooting
Connect to the right information to self-solve issues quickly and efficiently.
Lifecycle
View the various levels of maintenance for each release of a product over a period from initial release to the end of maintenance.