Описание
Spring Data Commons applications may be vulnerable to denial of service through resource exhaustion when attacker-controlled property path strings are passed to MappingContext property path resolution.
Affected versions: Spring Data Commons 4.0.0 through 4.0.5; 3.5.0 through 3.5.11; 3.4.0 through 3.4.14.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 3.4.0 (включая) до 3.4.15 (исключая)Версия от 3.5.0 (включая) до 3.5.12 (исключая)Версия от 4.0.0 (включая) до 4.0.6 (исключая)
Одно из
cpe:2.3:a:broadcom:spring_data_commons:*:*:*:*:*:*:*:*
cpe:2.3:a:broadcom:spring_data_commons:*:*:*:*:*:*:*:*
cpe:2.3:a:broadcom:spring_data_commons:*:*:*:*:*:*:*:*
EPSS
Процентиль: 29%
0.00363
Низкий
7.5 High
CVSS3
Дефекты
CWE-400
Связанные уязвимости
CVSS3: 7.5
redhat
2 месяца назад
Spring Data Commons applications may be vulnerable to denial of service through resource exhaustion when attacker-controlled property path strings are passed to MappingContext property path resolution. Affected versions: Spring Data Commons 4.0.0 through 4.0.5; 3.5.0 through 3.5.11; 3.4.0 through 3.4.14.
EPSS
Процентиль: 29%
0.00363
Низкий
7.5 High
CVSS3
Дефекты
CWE-400