Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreSpring Tools for Eclipse renders Spring Boot starter wizard dependency tooltips in a native embedded browser (SWT Browser) with JavaScript enabled. Using untrusted and compromised Initializr endpoints for the Spring Boot starter wizard can result in arbitrary script execution inside the embedded browser when a developer hovers a dependency checkbox in the New Spring Starter Project wizard. Impact is limited to in-IDE UI spoofing and outbound network beaconing rather than full code execution.
Spring Tools for Eclipse:
All versions prior to version 5 (no longer supported) are also affected.
Spring Tools for VSCode / Cursor / Theia are not affected, as the affected wizard and tooltip components are specific to the Eclipse IDE.
Users of affected versions should upgrade to the corresponding fixed version.
| Fix version | Availability |
|---|---|
| 5.3.0 | OSS |
No further mitigation steps are necessary.
Workaround for unpatched versions: Only configure trusted Spring Initializr service URLs (avoid custom or untrusted endpoints), and ensure network access to the configured Initializr endpoint is not subject to man-in-the-middle interception (e.g. use HTTPS and a trusted network path).
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N (4.2, Medium)To report a security vulnerability for a project within the Spring portfolio, see the Security Policy