Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreStarting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution.
This affects the live information feature across all environments (Eclipse, Visual Studio Code, Theia, Cursor) except the recently introduced extension for Claude Code.
Spring Tools for Eclipse:
Spring Tools for VSCode / Cursor / Theia:
All versions prior to version 5 (no longer supported) are also affected.
Users of affected versions should upgrade to the corresponding fixed version.
Spring Tools for Eclipse:
| Fix version | Availability |
|---|---|
| 5.3.0 | OSS |
Spring Tools for VSCode / Cursor / Theia:
| Fix version | Availability |
|---|---|
| 2.3.0 | OSS |
No further mitigation steps are necessary.
Workaround for unpatched versions: disable the live information enablement when starting Spring Boot applications from within the IDE.
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy