Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-22271

Опубликовано: 09 июл. 2024
Источник: redhat
CVSS3: 7.5

Описание

In Spring Cloud Function framework, versions 4.1.x prior to 4.1.2, 4.0.x prior to 4.0.8 an application is vulnerable to a DOS attack when attempting to compose functions with non-existing functions. Specifically, an application is vulnerable when all of the following are true: User is using Spring Cloud Function Web module Affected Spring Products and Versions Spring Cloud Function Framework 4.1.0 to 4.1.2 4.0.0 to 4.0.8 References https://spring.io/security/cve-2022-22979   https://checkmarx.com/blog/spring-function-cloud-dos-cve-2022-22979-and-unintended-function-invocation/  History 2020-01-16: Initial vulnerability report published.

A flaw was found in the Spring Cloud Function framework. Affected versions of this package are vulnerable to denial of service (DoS) when attempting to compose functions with nonexisting functions. This flaw allows an attacker to trigger a cache overflow.

Отчет

The vulnerability in the Spring Cloud Function framework, which allows an attacker to trigger a cache overflow by attempting to compose functions with nonexisting functions, represents a important severity issue due to its potential to facilitate Denial of Service (DoS) attacks. Such attacks can exploit the cache overflow mechanism to consume excessive computational resources, thereby degrading system performance and rendering the application unavailable to legitimate users.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Clients 2org.springframework.cloud/spring-cloud-function-contextNot affected
Red Hat Data Grid 8org.springframework.cloud/spring-cloud-function-contextNot affected
Red Hat JBoss Data Grid 7org.springframework.cloud/spring-cloud-function-contextWill not fix
Red Hat JBoss Enterprise Application Platform 7spring-cloud-function-contextNot affected
Red Hat JBoss Enterprise Application Platform 8spring-cloud-function-contextNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packorg.springframework.cloud/spring-cloud-function-contextAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2296608spring-cloud-function-context: Spring Cloud Function Web DOS Vulnerability

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 8.2
nvd
больше 1 года назад

In Spring Cloud Function framework, versions 4.1.x prior to 4.1.2, 4.0.x prior to 4.0.8 an application is vulnerable to a DOS attack when attempting to compose functions with non-existing functions. Specifically, an application is vulnerable when all of the following are true: User is using Spring Cloud Function Web module Affected Spring Products and Versions Spring Cloud Function Framework 4.1.0 to 4.1.2 4.0.0 to 4.0.8 References https://spring.io/security/cve-2022-22979   https://checkmarx.com/blog/spring-function-cloud-dos-cve-2022-22979-and-unintended-function-invocation/  History 2020-01-16: Initial vulnerability report published.

CVSS3: 8.2
github
больше 1 года назад

Spring Cloud Function Framework vulnerable to Denial of Service

CVSS3: 8.2
fstec
больше 1 года назад

Уязвимость веб-модуля программной платформы Spring Cloud Function, позволяющая нарушителю выполнить атаку типа «отказ в обслуживании»

7.5 High

CVSS3