Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-34053

Опубликовано: 27 нояб. 2023
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

In Spring Framework versions 6.0.0 - 6.0.13, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable when all of the following are true:

  • the application uses Spring MVC or Spring WebFlux
  • io.micrometer:micrometer-core is on the classpath
  • an ObservationRegistry is configured in the application to record observations Typically, Spring Boot applications need the org.springframework.boot:spring-boot-actuator dependency to meet all conditions.

Отчет

Red Hat Products are not affected by this vulnerability.

Меры по смягчению последствий

As a temporary workaround, Spring Boot 3.0.x and 3.1.x users can choose to disable web framework observations with the following property: management.metrics.enable.http.server.requests=false

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apache Camel for Spring Boot 3springframeworkNot affected
Red Hat Data Grid 8springframeworkNot affected
Red Hat Fuse 7springframeworkNot affected
Red Hat JBoss Data Grid 7springframeworkNot affected
Red Hat JBoss Enterprise Application Platform 7springframeworkNot affected
streams for Apache KafkaspringframeworkNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2251920springframework: io.micrometer: micrometer-core classpath vulnerable to denial of service

EPSS

Процентиль: 63%
0.00453
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 1 года назад

In Spring Framework versions 6.0.0 - 6.0.13, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable when all of the following are true: * the application uses Spring MVC or Spring WebFlux * io.micrometer:micrometer-core is on the classpath * an ObservationRegistry is configured in the application to record observations Typically, Spring Boot applications need the org.springframework.boot:spring-boot-actuator dependency to meet all conditions.

CVSS3: 5.3
nvd
больше 1 года назад

In Spring Framework versions 6.0.0 - 6.0.13, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable when all of the following are true: * the application uses Spring MVC or Spring WebFlux * io.micrometer:micrometer-core is on the classpath * an ObservationRegistry is configured in the application to record observations Typically, Spring Boot applications need the org.springframework.boot:spring-boot-actuator dependency to meet all conditions.

CVSS3: 5.3
debian
больше 1 года назад

In Spring Framework versions 6.0.0 - 6.0.13, it is possible for a user ...

CVSS3: 7.5
github
больше 1 года назад

Spring Framework vulnerable to denial of service

CVSS3: 7.5
fstec
больше 1 года назад

Уязвимость программной платформы Spring Framework, связанная с неограниченным распределением ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 63%
0.00453
Низкий

7.5 High

CVSS3