Описание
Spring HATEOAS maintains an unbounded static cache of StringLinkRelation instances keyed on attacker-supplied strings.
Affected versions:
Spring HATEOAS 1.5.0 through 1.5.6; 2.3.0 through 2.3.4; 2.4.0 through 2.4.1; 2.5.0 through 2.5.2; 3.0.0 through 3.0.3.
A flaw was found in Spring HATEOAS. An attacker can exploit this vulnerability by supplying specially crafted strings, which are then used as keys in an unbounded static cache. This can lead to resource exhaustion, causing a denial of service (DoS) for the application.
Отчет
This is an Important denial of service flaw in Spring HATEOAS, affecting Red Hat JBoss Fuse. The vulnerability arises from an unbounded static cache that can be exhausted by attacker-supplied strings, leading to resource unavailability. This impact is considered Important due to the potential for remote, unauthenticated attackers to disrupt service.
Меры по смягчению последствий
To mitigate the risk of denial of service, restrict network access to applications that use Spring HATEOAS to trusted clients and networks. Implementing rate limiting on incoming requests can also help reduce the impact by limiting the volume of attacker-supplied strings that can trigger cache exhaustion. Ensure that any changes to network configurations are thoroughly tested to avoid disrupting legitimate service.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Fuse 7 | spring-hateoas | Fix deferred |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
Spring HATEOAS maintains an unbounded static cache of StringLinkRelation instances keyed on attacker-supplied strings. Affected versions: Spring HATEOAS 1.5.0 through 1.5.6; 2.3.0 through 2.3.4; 2.4.0 through 2.4.1; 2.5.0 through 2.5.2; 3.0.0 through 3.0.3.
Spring HATEOAS heap exhaustion through unbounded internal caching
7.5 High
CVSS3