Описание
In Spring Boot versions 2.7.0 - 2.7.17, 3.0.0-3.0.12 and 3.1.0-3.1.5, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable when all of the following are true:
- the application uses Spring MVC or Spring WebFlux
- org.springframework.boot:spring-boot-actuator is on the classpath
Отчет
Red Hat does not ship any spring integration in the RHEL log4j package, therefore the log4j package is not affected by this issue in Red Hat Enterprise Linux 8 & 9. Red Hat Single Sign-On provides Spring Boot adapters, but does not provide the affected code and is not affected by this flaw.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| A-MQ Clients 2 | spring-boot | Not affected | ||
| Migration Toolkit for Runtimes | spring-boot | Not affected | ||
| Red Hat AMQ Broker 7 | spring-boot | Affected | ||
| Red Hat build of Apache Camel for Spring Boot 3 | spring-boot | Not affected | ||
| Red Hat build of OptaPlanner 8 | spring-boot | Not affected | ||
| Red Hat Data Grid 8 | spring-boot | Not affected | ||
| Red Hat Decision Manager 7 | spring-boot | Out of support scope | ||
| Red Hat Enterprise Linux 8 | log4j:2/log4j | Not affected | ||
| Red Hat Enterprise Linux 9 | log4j | Not affected | ||
| Red Hat Integration Camel K 1 | spring-boot | Will not fix |
Показывать по
Дополнительная информация
Статус:
6.5 Medium
CVSS3
Связанные уязвимости
In Spring Boot versions 2.7.0 - 2.7.17, 3.0.0-3.0.12 and 3.1.0-3.1.5, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable when all of the following are true: * the application uses Spring MVC or Spring WebFlux * org.springframework.boot:spring-boot-actuator is on the classpath
Spring Boot Actuator denial of service vulnerability
Уязвимость фреймворка создания веб-приложений Spring Boot, связанная с некорректной зачисткой или освобождением ресурсов, позволяющая нарушителю вызвать отказ в обслуживании
6.5 Medium
CVSS3