Josh Cummings

Josh Cummings

Josh has been a software engineer for over 15 years building enterprise applications across multiple industries. He has long been passionate about application security and loves opportunities to mentor and to learn from others about security awareness.

When Josh isn't hacking away at code, he is either running, playing basketball, camping, or reading a Brandon Sanderson novel.

Recent Blog posts by Josh Cummings

Spring Security 5.3 goes GA

Releases | March 05, 2020 | ...
On behalf of the community, it is my pleasure to announce the general availability of Spring Security 5.3. This release is the result of the work that went into 5.3.0.M1, 5.3.0.RC1, and 5.3.0.RELEASE. In combination they close 200+ tickets. You can find the highlights of 5.3 in the What’s new section of the Spring Security reference. As always, we look forward to hearing your feedback! Project Site | Reference | Help

Spring Security OAuth 2.0 Roadmap Update

News | November 14, 2019 | ...
Note See the latest announcement on Announcing the Spring Authorization Server. This post is a follow-up to Next Generation OAuth 2.0 Support with Spring Security Current State In the Spring Security 5.x release train, we’ve endeavored to replace and simplify the feature set found in the Spring Security OAuth 2.x legacy project. In the process, we’ve also added numerous new features, including support for OpenID Connect 1.0. We are pleased to announce that as of the 5.2 release, we are very close to feature parity with the client and resource server legacy support. What remains is quite…

Spring Security 5.2.1 and 5.1.7 Released

Releases | November 04, 2019 | ...
On behalf of the community, I’m pleased to announce the release of Spring Security 5.2.1 (release notes) and 5.1.7 (release notes). These releases deliver bug fixes along with some minor improvements. Users are encouraged to update to the latest patch release. Project Site | Reference | Help

Spring Security 5.1.6 and 5.0.13 Released

Releases | August 05, 2019 | ...
On behalf of the community I am pleased to announce the release of Spring Security 5.1.6 (changelog) and 5.0.13 (changelog). These releases deliver bug fixes along with some minor improvements. Users are encouraged to update to the latest patch release. Project Site | Reference | Help

CVE-2019-11272: Spring Security 4.2.13 Released

Releases | June 19, 2019 | ...
We have released Spring Security 4.2.13 to address CVE-2019-11272: PlaintextPasswordEncoder authenticates encoded passwords that are null. Users are encouraged to update immediately. With Spring Boot, you can override the Spring Security version in Maven like so: Or in Gradle like so: Note that users of Spring Security 5+ are not affected by this vulnerability.

CVE-2019-11269: Spring Security OAuth 2.3.6, 2.2.5, 2.1.5, 2.0.18 Released

Releases | May 30, 2019 | ...
We have released Spring Security OAuth 2.3.6, 2.2.5, 2.1.5 and 2.0.18 to address CVE-2019-11269: Open Redirector in spring-security-oauth2. Please review the information in the CVE report and upgrade immediately. For additional changes included in each release, please refer to: 2.3.6 changelog 2.2.5 changelog 2.1.5 changelog 2.0.18 changelog NOTE: For users of Spring Boot 1.5.x and Spring IO Platform Cairo, it is highly recommended to override the spring-security-oauth version to the latest version containing the fix for the CVE. Please see the Mitigation section in the CVE report for detailed…

Spring Security 5.2.0.M2 Released

Releases | April 16, 2019 | ...
On behalf of the community, I’m pleased to announce the release of Spring Security 5.2.0.M2! This release includes 100+ updates. You can find the highlights below: OAuth 2.0 gh-6446 - Client Support for PKCE PKCE isn’t just for native or browser-based apps, but for any time we want to have a public client. Spring Security 5.2 introduces a secure way for backends to authenticate as public clients. gh-5350 - OpenID Connect RP-Initiated Logout gh-5465 - Ability to use symmetric keys with JwtDecoder gh-5397 - Ability for NimbusReactiveJwtDecoder to take a custom processor gh-6513 & gh-520…

Spring Security 5.1.4 Released

Releases | February 14, 2019 | ...
On behalf of the community I am pleased to announce the release of Spring Security 5.1.4 (changelog). This release provides a round of bug fixes and users are encouraged to update to the latest patch release. Project Site | Reference | Help

Spring Security 5.1.3, 5.0.11, 4.2.11 Released

Releases | January 11, 2019 | ...
On behalf of the community I am pleased to announce the release of Spring Security 5.1.3 (changelog), 5.0.11 (changelog), and 4.2.11 (changelog). This series of releases provides a round of bug fixes and users are encouraged to update to the latest patch release. Project Site | Reference | Help

Get ahead

VMware offers training and certification to turbo-charge your progress.

Learn more

Get support

Tanzu Spring offers support and binaries for OpenJDK™, Spring, and Apache Tomcat® in one simple subscription.

Learn more

Upcoming events

Check out all the upcoming events in the Spring community.

View all