Описание
In spring framework versions prior to 5.2.24 release+ ,5.3.27+ and 6.0.8+ , it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.
A flaw was found in Spring Framework. Certain versions of Spring Framework's Expression Language were not restricting the size of Spring Expressions. This could allow an attacker to craft a malicious Spring Expression to cause a denial of service on the server.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Fuse 7 | springframework | Affected | ||
RHINT Camel-Springboot 3.18.3.P1 | springframework | Fixed | RHSA-2023:2099 | 03.05.2023 |
RHINT Camel-Springboot 3.20.1 | springframework | Fixed | RHSA-2023:2100 | 03.05.2023 |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
In spring framework versions prior to 5.2.24 release+ ,5.3.27+ and 6.0.8+ , it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.
In spring framework versions prior to 5.2.24 release+ ,5.3.27+ and 6.0.8+ , it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.
In spring framework versions prior to 5.2.24 release+ ,5.3.27+ and 6.0 ...
Spring Framework vulnerable to denial of service
Уязвимость программной платформы Spring Framework, связанная с ошибками при обработке SpEL-выражений, позволяющая нарушителю выполнить произвольный код
EPSS
6.5 Medium
CVSS3