Spring Data 2021.2.1 和 2021.1.5 现已发布,这两个版本都附带了针对大多数 bug fixes 和依赖项升级的修复。
此外,其中还包括对一个漏洞的修复:
- CVE-2022-22980
“Spring Data MongoDB SpEL Expression Injection Vulnerability”
MongoDB 应用程序中的 SpEL 注入攻击,通过使用带有未过滤输入的参数化 SpEL 语句使用 @Query 或 @Aggregation 注释的存储库查询方法。
严重性:High
官方表示,这些新版本是对所有 Spring Data 生产场景的推荐升级。
各个模块、变更日志和文档的链接如下:
2021.2.1
- Spring Data Commons
2.7.1
- Artifacts - Javadoc - Documentation - Changelog - Spring Data JDBC
2.4.1
- Artifacts - Javadoc - Documentation - Changelog - Spring Data JPA
2.7.1
- Artifacts - Javadoc - Documentation - Changelog - Spring Data for Apache Geode
2.7.1
- Artifacts - Javadoc - Documentation - Changelog - Spring Data Neo4j
6.3.1
- Artifacts - Javadoc - Documentation - Changelog - Spring Data KeyValue
2.7.1
- Artifacts - Javadoc - Documentation - Changelog - Spring Data MongoDB
3.4.1
- Artifacts - Javadoc - Documentation - Changelog - Spring Data for Apache Cassandra
3.4.1
- Artifacts - Javadoc - Documentation - Changelog - Spring Data R2DBC
1.5.1
- Artifacts - Javadoc - Documentation - Changelog - Spring Data LDAP
2.7.1
- Artifacts - Javadoc - Documentation - Changelog - Spring Data Envers
2.7.1
- Artifacts - Javadoc - Documentation - Changelog - Spring Data REST
3.7.1
- Artifacts - Javadoc - Documentation - Changelog - Spring Data Redis
2.7.1
- Artifacts - Javadoc - Documentation - Changelog - Spring Data Elasticsearch
4.4.1
- Artifacts - Javadoc - Documentation - Changelog - Spring Data Couchbase
4.4.1
- Artifacts - Javadoc - Documentation - Changelog
2021.1.5
- Spring Data Commons
2.6.5
- Artifacts - Javadoc - Documentation - Changelog - Spring Data JDBC
2.3.5
- Artifacts - Javadoc - Documentation - Changelog - Spring Data JPA
2.6.5
- Artifacts - Javadoc - Documentation - Changelog - Spring Data for Apache Geode
2.6.5
- Artifacts - Javadoc - Documentation - Changelog - Spring Data Neo4j
6.2.5
- Artifacts - Javadoc - Documentation - Changelog - Spring Data KeyValue
2.6.5
- Artifacts - Javadoc - Documentation - Changelog - Spring Data MongoDB
3.3.5
- Artifacts - Javadoc - Documentation - Changelog - Spring Data for Apache Cassandra
3.3.5
- Artifacts - Javadoc - Documentation - Changelog - Spring Data R2DBC
1.4.5
- Artifacts - Javadoc - Documentation - Changelog - Spring Data LDAP
2.6.5
- Artifacts - Javadoc - Documentation - Changelog - Spring Data Envers
2.6.5
- Artifacts - Javadoc - Documentation - Changelog - Spring Data REST
3.6.5
- Artifacts - Javadoc - Documentation - Changelog - Spring Data Redis
2.6.5
- Artifacts - Javadoc - Documentation - Changelog - Spring Data Elasticsearch
4.3.5
- Artifacts - Javadoc - Documentation - Changelog - Spring Data Couchbase
4.3.5
- Artifacts - Javadoc - Documentation - Changelog