Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-38828

Опубликовано: 18 нояб. 2024
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

Spring MVC controller methods with an @RequestBody byte[] method parameter are vulnerable to a DoS attack.

A flaw was found in the Spring Framework. In certain versions, Spring MVC controller methods with a @RequestBody byte[] method parameter are vulnerable to a denial of service attack.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AMQ Broker 7spring-webmvcFix deferred
Red Hat build of Apache Camel for Spring Boot 4spring-webmvcNot affected
Red Hat build of Apache Camel - HawtIO 4spring-webmvcNot affected
Red Hat Build of Keycloakspring-webmvcWill not fix
Red Hat build of OptaPlanner 8spring-webmvcFix deferred
Red Hat Data Grid 8spring-webmvcNot affected
Red Hat Fuse 7spring-webmvcOut of support scope
Red Hat Integration Camel K 1spring-webmvcAffected
Red Hat JBoss Data Grid 7spring-webmvcOut of support scope
Red Hat JBoss Enterprise Application Platform 7spring-webmvcNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=2326889org.springframework:spring-webmvc: DoS via Spring MVC controller method with byte[] parameter

EPSS

Процентиль: 52%
0.00724
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 2 года назад

Spring MVC controller methods with an @RequestBody byte[] method parameter are vulnerable to a DoS attack.

CVSS3: 5.3
nvd
почти 2 года назад

Spring MVC controller methods with an @RequestBody byte[] method parameter are vulnerable to a DoS attack.

CVSS3: 5.3
debian
почти 2 года назад

Spring MVC controller methods with an @RequestBody byte[]method parame ...

CVSS3: 5.3
github
почти 2 года назад

Spring MVC controller vulnerable to a DoS attack

EPSS

Процентиль: 52%
0.00724
Низкий

5.3 Medium

CVSS3