Описание
Spring MVC controller methods with an @RequestBody byte[] method parameter are vulnerable to a DoS attack.
A flaw was found in the Spring Framework. In certain versions, Spring MVC controller methods with a @RequestBody byte[] method parameter are vulnerable to a denial of service attack.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat AMQ Broker 7 | org.springframework/spring-webmvc | Fix deferred | ||
| Red Hat build of Apache Camel for Spring Boot 4 | org.springframework/spring-webmvc | Not affected | ||
| Red Hat build of Apache Camel - HawtIO 4 | org.springframework/spring-webmvc | Not affected | ||
| Red Hat Build of Keycloak | org.springframework/spring-webmvc | Affected | ||
| Red Hat build of OptaPlanner 8 | org.springframework/spring-webmvc | Fix deferred | ||
| Red Hat Data Grid 8 | org.springframework/spring-webmvc | Not affected | ||
| Red Hat Fuse 7 | org.springframework/spring-webmvc | Out of support scope | ||
| Red Hat Integration Camel K 1 | org.springframework/spring-webmvc | Affected | ||
| Red Hat JBoss Data Grid 7 | org.springframework/spring-webmvc | Out of support scope | ||
| Red Hat JBoss Enterprise Application Platform 7 | org.springframework/spring-webmvc | Not affected |
Показывать по
10
Дополнительная информация
Статус:
Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=2326889org.springframework:spring-webmvc: DoS via Spring MVC controller method with byte[] parameter
EPSS
Процентиль: 18%
0.00058
Низкий
5.3 Medium
CVSS3
Связанные уязвимости
CVSS3: 5.3
ubuntu
около 1 года назад
Spring MVC controller methods with an @RequestBody byte[] method parameter are vulnerable to a DoS attack.
CVSS3: 5.3
nvd
около 1 года назад
Spring MVC controller methods with an @RequestBody byte[] method parameter are vulnerable to a DoS attack.
CVSS3: 5.3
debian
около 1 года назад
Spring MVC controller methods with an @RequestBody byte[]method parame ...
CVSS3: 5.3
github
около 1 года назад
Spring MVC controller vulnerable to a DoS attack
EPSS
Процентиль: 18%
0.00058
Низкий
5.3 Medium
CVSS3