Описание
Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a regular expression, denial of service attack.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat JBoss A-MQ 6 | spring | Not affected | ||
Red Hat JBoss BRMS 5 | spring | Not affected | ||
Red Hat JBoss Data Virtualization 6 | spring | Out of support scope | ||
Red Hat JBoss Enterprise Application Platform 5 | spring | Not affected | ||
Red Hat JBoss Fuse 6 | spring | Not affected | ||
Red Hat JBoss Fuse Integration Service 2 | spring | Fix deferred | ||
Red Hat JBoss Fuse Service Works 6 | spring | Not affected | ||
Red Hat JBoss SOA Platform 5 | spring | Out of support scope | ||
Red Hat Mobile Application Platform 4 | spring | Not affected | ||
Red Hat OpenStack Platform 10 (Newton) | opendaylight | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
4.8 Medium
CVSS3
Связанные уязвимости
Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a regular expression, denial of service attack.
Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a regular expression, denial of service attack.
Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior ...
Denial of Service in org.springframework:spring-core
Уязвимость программной платформы Spring Framework, существующая из-за недостаточной проверки входных данных, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
4.8 Medium
CVSS3