Spring Framework CVE: How it affects FusionAuth (TLDR: It doesn't)

FusionAuth does not use Spring and is not affected by CVE-2022-22965

Authors

Published: April 5, 2022


The recent announcement of CVE-2022-22965, where “a Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding,” has some folks asking if FusionAuth is affected. This CVE is also known as the “Spring4Shell” vulnerability.

FusionAuth is not affected by this vulnerability in Spring. FusionAuth uses a different MVC framework, Prime, so there is no way that any FusionAuth applications could be compromised.

FusionAuth is not affected by this vulnerability.

Spring is a popular application framework and is used in many Java projects, both open source and commercial. When a CVE like this comes out, it makes sense to check all of your applications for the issue. Security is important to us and we understand why customers and users would reach out about this.

In conclusion, FusionAuth is not affected by the Spring vulnerability.

To learn more about the CVE, you can:

A bit more about security and FusionAuth

Beyond this specific vulnerability, we want to assure readers that FusionAuth takes security very seriously.

This commitment includes, but is not limited to:

More on security

Subscribe to The FusionAuth Newsletter

A newsletter for developers covering techniques, technical guides, and the latest product innovations coming from FusionAuth.

Just dev stuff. No junk.