Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-20883

Опубликовано: 18 мая 2023
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

In Spring Boot versions 3.0.0 - 3.0.6, 2.7.0 - 2.7.11, 2.6.0 - 2.6.14, 2.5.0 - 2.5.14 and older unsupported versions, there is potential for a denial-of-service (DoS) attack if Spring MVC is used together with a reverse proxy cache.

A flaw was found in Spring Boot, occurring prominently in Spring MVC with a reverse proxy cache. This issue requires Spring MVC to have auto-configuration enabled and the application to use Spring Boot's welcome page support, either static or templated, resulting in the application being deployed behind a proxy that caches 404 responses. This issue may cause a denial of service (DoS) attack.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Clients 2spring-bootNot affected
Migration Toolkit for Runtimesspring-bootAffected
Red Hat AMQ Broker 7spring-bootNot affected
Red Hat Data Grid 8spring-bootNot affected
Red Hat Enterprise Linux 8log4j:2/log4jAffected
Red Hat Enterprise Linux 9log4jAffected
Red Hat Integration Camel K 1spring-bootNot affected
Red Hat JBoss Data Grid 7spring-bootOut of support scope
Red Hat JBoss Enterprise Application Platform 6spring-bootOut of support scope
Red Hat JBoss Enterprise Application Platform 7spring-bootNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2209342spring-boot: Spring Boot Welcome Page DoS Vulnerability

EPSS

Процентиль: 61%
0.00408
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
больше 2 лет назад

In Spring Boot versions 3.0.0 - 3.0.6, 2.7.0 - 2.7.11, 2.6.0 - 2.6.14, 2.5.0 - 2.5.14 and older unsupported versions, there is potential for a denial-of-service (DoS) attack if Spring MVC is used together with a reverse proxy cache.

CVSS3: 7.5
github
больше 2 лет назад

Spring Boot Welcome Page Denial of Service

EPSS

Процентиль: 61%
0.00408
Низкий

7.5 High

CVSS3