Multiple Spring Framework and Spring Security Vulnerabilities 

Issue date: 26-04-2018
Affects versions: 12.2, 11.2, 10.2

Issue ID: SECURITY-47

Affected Product Version(s)
These vulnerabilities affects all versions of both CMS and delivery applications based on Hippo CMS prior to 12.3.0, 12.2.1, 11.2.7, and 10.2.11.

Severity 

High

Description

5 vulnerabilities have been reported against the Spring Framework and/or Spring Security libraries, which allow various attacks, including reflective file download and denial of service. Customers may also be vulnerable in other ways via use of these libraries in their own code. 

See CVE-2015-5211CVE-2015-0201CVE-2015-3192CVE-2016-5007CVE-2016-9878

The affected Spring Framework and Spring Security libraries have been updated in all supported CMS maintenance versions 10.2.11, 11.2.7, 12.2.1, and 12.3.0.

  • For 10.2.11, Spring Framework was upgraded from 4.1.4 to 4.3.15
  • For 11.2.7, 12.2.1, and 12.3.0, Spring Framework was upgraded from 4.2.6 to 4.3.15
  • For 12.2.1 and 12.3.0, Spring Security was upgraded from 4.0.4 to 4.2.5; also Spring Security JWT was upgraded from 1.0.4 to 1.0.9

Instructions

Every CMS customer is strongly advised to upgrade as soon as possible to the latest CMS maintenance release as indicated above, or higher.

Because the upgrade for these CMS maintenance versions may require some additonal steps and verification, specific upgrade documentation is available to our customers for upgrading to version 10.2.11, 11.2.7, or to 12.2.1 and 12.3.0 (login required).