Our takeCanadian Cyber Centre issued an advisory on vulnerabilities in Spring Tools for Eclipse (≤5.2.0) and VSCode/Cursor/Theia (≤2.2.0). Update to the latest version.Cyber Resilience desk
Sources (1)
- cccs · cccs
What this means for you — Security leader:Update Spring Tools for Eclipse to >5.2.0 and Spring Tools for VSCode/Cursor/Theia to >2.2.0 if you use them in your development environments.
What this means for you — Lean IT orgs:If your team uses Spring Tools for Eclipse or VSCode, update them now to the latest version.
What this means for you — MSP:Check client estates for Spring Tools for Eclipse ≤5.2.0 or Spring Tools for VSCode/Cursor/Theia ≤2.2.0 and push updates.
What this means for you — Researcher:Review the CCCS advisory for Spring Tools for Eclipse and VSCode extensions; affected versions are now public.