The Spring Framework project has recently discovered a security vulnerability which may allow a remote attacker to inject malicious code into an application that is using the Spring Framework. For more information on this security vulnerability kindly refer the following document:
Apache Geronimo uses the Spring Framework to implement some functions in the ActiveMQ console and the vulnerable Spring libraries are included in the Geronimo jar repository. It is not believed that the console application is vulnerable to this attack, but any application that is using the included version of the Spring framework might be. Users are advised to update the version of the Spring libraries to remove the chance that this exploit can be used.
These issues have been fixed in Spring Framework version 2.5.6.SEC02.
It is recommended that you move to Apache Geronimo v2.1.6 or v2.2.1. These versions include the updated Spring libraries.
If you wish to remain on an existing version of Geronimo, the installation can be patched to avoid the vulnerability. The following steps will upgrade the Spring framework libraries used by the server.