Описание
Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources. More precisely, an application can be vulnerable when all the following are true:
- the application is using Spring MVC or Spring WebFlux
- the application is serving static resources from the file system
- the application is running on a Windows platform
When all the conditions above are met, the attacker can send malicious requests that are slow to resolve and that can keep HTTP connections in use. This can cause a Denial of Service on the application.
A flaw was found in Spring MVC and Spring WebFlux applications. When an application is configured to serve static resources from the file system on a Windows platform, a remote attacker can send specially crafted requests that are slow to resolve. This can keep HTTP connections in use, leading to a Denial of Service (DoS) on the application.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat build of Apache Camel - HawtIO 4 | spring-webflux | Fix deferred | ||
| Red Hat Fuse 7 | spring-webflux | Out of support scope | ||
| Red Hat JBoss Enterprise Application Platform 7 | spring-webflux | Out of support scope | ||
| Red Hat JBoss Enterprise Application Platform 8 | opentelemetry-javaagent-spring-webflux-5.0 | Fix deferred | ||
| Red Hat JBoss Enterprise Application Platform 8 | opentelemetry-spring-webflux-5.3 | Fix deferred | ||
| Red Hat JBoss Enterprise Application Platform 8 | spring-webflux | Fix deferred | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | opentelemetry-javaagent-spring-webflux-5.0 | Fix deferred | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | opentelemetry-spring-webflux-5.3 | Fix deferred | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | spring-webflux | Out of support scope |
Показывать по
Дополнительная информация
Статус:
5.3 Medium
CVSS3
Связанные уязвимости
Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources. More precisely, an application can be vulnerable when all the following are true: * the application is using Spring MVC or Spring WebFlux * the application is serving static resources from the file system * the application is running on a Windows platform When all the conditions above are met, the attacker can send malicious requests that are slow to resolve and that can keep HTTP connections in use. This can cause a Denial of Service on the application.
Spring MVC and WebFlux applications are vulnerable to Denial of Servic ...
Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources
5.3 Medium
CVSS3