Описание
A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some circumstances, temp files may remain not deleted after the request is fully processed. This allows an attacker to consume available disk space.
Older, unsupported versions are also affected.
A flaw was found in Spring WebFlux, a component of the Spring Framework. A remote attacker can exploit this vulnerability by sending specially crafted multipart requests to a WebFlux server application. When processing these requests, the server creates temporary files that, under certain conditions, are not properly deleted. This can lead to an accumulation of temporary files, consuming available disk space and potentially causing a Denial of Service (DoS) for the affected system.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat build of Apache Camel - HawtIO 4 | spring-webflux | Fix deferred | ||
| Red Hat Fuse 7 | spring-webflux | Out of support scope | ||
| Red Hat JBoss Enterprise Application Platform 7 | spring-webflux | Out of support scope | ||
| Red Hat JBoss Enterprise Application Platform 8 | opentelemetry-javaagent-spring-webflux-5.0 | Fix deferred | ||
| Red Hat JBoss Enterprise Application Platform 8 | opentelemetry-spring-webflux-5.3 | Fix deferred | ||
| Red Hat JBoss Enterprise Application Platform 8 | spring-webflux | Fix deferred | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | opentelemetry-javaagent-spring-webflux-5.0 | Out of support scope | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | opentelemetry-spring-webflux-5.3 | Fix deferred | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | spring-webflux | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some circumstances, temp files may remain not deleted after the request is fully processed. This allows an attacker to consume available disk space. Older, unsupported versions are also affected.
A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some circumstances, temp files may remain not deleted after the request is fully processed. This allows an attacker to consume available disk space. Older, unsupported versions are also affected.
A WebFlux server application that processes multipart requests creates ...
Spring Framework DoS with Multipart Temp Files in WebFlux
EPSS
6.5 Medium
CVSS3