Spring Insight Known Vulnerabilities and Issues

Components of Spring Insight

Spring Insight is built with the following components. Please see the security advisories information for each component for more information on the security vulnerabilities and issues that may affect that component.

Component Security advisories
Dojo Dojo security advisories

Spring Insight is built using the following versions of these components

Spring Insight version Dojo version
1.0.2.M2 1.4.0

Spring Insight is vulnerable to the Dojo security issues announced on 11 March 2010 by default. Spring Insight users are advised not to browse untrusted sites whilst Spring Insight is running and to stop the Spring Insight web application when not being used.

The next release of Spring Insight will include an updated Dojo component that is not vulnerable to the issues announced on 11 March 2010.

Known Vulnerabilities in Spring Insight

There are no known vulnerabilities in Spring Insight over and above those known to exist in the components of Spring Insight