Josh Cummings

Josh Cummings

Josh has been a software engineer for over 15 years building enterprise applications across multiple industries. He has long been passionate about application security and loves opportunities to mentor and to learn from others about security awareness.

When Josh isn't hacking away at code, he is either running, playing basketball, camping, or reading a Brandon Sanderson novel.

Blog posts by Josh Cummings

Spring Security 6.4.0 goes GA!

Releases | November 19, 2024 | ...

On behalf of the Spring Security team and everyone who contributed to this release, I am delighted to announce the general availability of Spring Security 6.4.0 from Maven Central!

The 6.4 release brings several compelling features including:

  • Support for Passkeys and One-Time Tokens
  • Simplified OAuth 2.0 Configuration
  • Refreshable SAML 2.0 Asserting Parties, and
  • New method security annotations and capabilities

To find out more about what’s new, see the what's new section of the documentation.

This release will be included in the upcoming Spring Boot 3.4 GA release. We'd like to hear from you…

Spring LDAP 2.4.4 and 3.2.8 are now available

Releases | November 19, 2024 | ...

On behalf of the team and everyone who has contributed, I am pleased to announce that Spring LDAP 2.4.4 and 3.2.8 are out! In both cases, the releases are mostly composed of bug fixes and dependency upgrades.

Importantly, these release addresses CVE-2024-38829.

To learn more, please visit the 2.4.4 and 3.2.8 release summaries.

Commercial customers using Spring Boot 2.7, 3.0, or 3.1 can update to Spring Boot 2.7.22.5, 3.0.17.5, or 3.1.13.5 respectively to receive the corresponding LDAP releases 2.4.4, 3.0.10, and 3.1.8. These hotfix versions are available now on the Spring commercial artifact repository and can be accessed with a Spring Enterprise Subscription

Spring Security 6.2.8 and 6.3.5 are now available

Releases | November 19, 2024 | ...

On behalf of the team and everyone who has contributed, I am pleased to announce that Spring Security 6.2.8 and 6.3.5 are out! In all cases, the releases are mostly composed of bug fixes, dependency upgrades, and documentation improvements.

Importantly, these releases address CVE-2024-38827.

To learn more, please visit the 6.2.8 and 6.3.5 release summaries.

Commercial customers using Spring Boot 2.7, 3.0, or 3.1 can update to Spring Boot 2.7.22.5, 3.0.17.5, or 3.1.13.5 respectively to receive the corresponding Security releases 5.7.14, 6.0.14, and 6.1.12. These hotfix versions are available now on the Spring commercial artifact repository and can be accessed with a Spring Enterprise Subscription

Spring Security 6.3.0-RC1 is available now

Releases | April 18, 2024 | ...

On behalf of the team and everyone who has contributed, I am pleased to announce that the release candidate of Spring Security 6.3 is released.

The 6.3 release brings several compelling features including

  • Long-term JDK serialization backward compatibility
  • New method security annotations and capabilities
  • Compromised password checking, and
  • OAuth 2.0 Token Exchange support

You can read more about each of these in the What's New section of the 6.3 documentation and also see the exhaustive list of of features across the 6.3 release in the release pages for 6.3.0-M1, 6.3.0-M2, 6.3.0-M3, and 6.3.0-RC1

Spring Security 5.6.12, 5.7.10, 5.8.5, 6.0.5, and 6.1.2 are available now, including fixes for CVE-2023-34034 and CVE-2023-34035

Releases | July 24, 2023 | ...

On behalf of the team and everyone who has contributed, I am pleased to announce that the Spring Security 5.6.12, 5.7.10, 5.8.5, 6.0.5, and 6.1.2 are available now.

Please refer to the releases page for more detail on what is included in each release.

Those versions fix the following CVEs:

It is also important to remember that the 5.8 version of Spring Security is a special release designed to help you to migrate to Spring Security 6.0, therefore if you are planning to upgrade your applications, using that version combined with the special migration guide

Get ahead

VMware offers training and certification to turbo-charge your progress.

Learn more

Get support

Tanzu Spring offers support and binaries for OpenJDK™, Spring, and Apache Tomcat® in one simple subscription.

Learn more

Upcoming events

Check out all the upcoming events in the Spring community.

View all