Описание
Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux
Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources.
Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
Пакеты
org.springframework:spring-webmvc
>= 7.0.0, <= 7.0.7
7.0.8
org.springframework:spring-webflux
>= 7.0.0, <= 7.0.7
7.0.8
org.springframework:spring-webmvc
>= 6.2.0, <= 6.2.18
6.2.19
org.springframework:spring-webflux
>= 6.2.0, <= 6.2.18
6.2.19
org.springframework:spring-webmvc
>= 6.1.0, <= 6.1.21
Отсутствует
org.springframework:spring-webflux
>= 6.1.0, <= 6.1.21
Отсутствует
org.springframework:spring-webmvc
<= 5.3.39
Отсутствует
org.springframework:spring-webflux
<= 5.3.39
Отсутствует
Связанные уязвимости
Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
Spring MVC and WebFlux applications are vulnerable to Denial of Servic ...