Описание
In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.
A flaw found was found in Spring Framework. This flaw allows a malicious user to use a specially crafted SpEL expression that causes a denial of service (DoS).
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
A-MQ Clients 2 | springframework | Not affected | ||
Logging Subsystem for Red Hat OpenShift | openshift-logging/elasticsearch6-rhel8 | Not affected | ||
Migration Toolkit for Applications 6 | org.keycloak-keycloak-parent | Not affected | ||
Migration Toolkit for Runtimes | org.keycloak-keycloak-parent | Not affected | ||
Red Hat Data Grid 8 | springframework | Not affected | ||
Red Hat Decision Manager 7 | springframework | Out of support scope | ||
Red Hat Enterprise Linux 8 | log4j:2/log4j | Not affected | ||
Red Hat Enterprise Linux 9 | log4j | Not affected | ||
Red Hat Integration Camel K 1 | springframework | Not affected | ||
Red Hat Integration Camel Quarkus 1 | springframework | Not affected |
Показывать по
Дополнительная информация
Статус:
5.3 Medium
CVSS3
Связанные уязвимости
In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.
In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.
In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELE ...
Spring Framework vulnerable to denial of service via specially crafted SpEL expression
Уязвимость программной платформы Spring Framework, связанная с неограниченным распределением ресурсов, позволяющая нарушителю вызвать отказ в обслуживании
5.3 Medium
CVSS3