Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hh26-6xwr-ggv7

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Denial of service in Spring Framework

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.

Пакеты

Наименование

org.springframework:spring-beans

maven
Затронутые версииВерсия исправления

<= 5.2.21.RELEASE

5.2.22.RELEASE

Наименование

org.springframework:spring-beans

maven
Затронутые версииВерсия исправления

>= 5.3.0, < 5.3.20

5.3.20

EPSS

Процентиль: 52%
0.00288
Низкий

7.5 High

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 3 лет назад

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.

CVSS3: 5.3
redhat
около 3 лет назад

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.

CVSS3: 5.3
nvd
около 3 лет назад

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.

CVSS3: 5.3
debian
около 3 лет назад

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupp ...

EPSS

Процентиль: 52%
0.00288
Низкий

7.5 High

CVSS3

Дефекты

CWE-770