Updated springframework packages fix security vulnerabilities:
Jaxb2RootElementHttpMessageConverter in Spring MVC processes external XML entities (CVE-2014-0054).
Spring MVC introduces a cross-site scripting vulnerability if the action on a Spring form is not specified (CVE-2014-1904).