Описание
Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests.
Affected versions: Spring Framework 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, 5.3.0 through 5.3.48.
A flaw was found in Spring WebFlux applications. A remote attacker could exploit this vulnerability by sending specially crafted multipart requests, leading to a Denial of Service (DoS) condition. This could make the application unavailable to legitimate users.
Отчет
Red Hat ships Spring WebFlux in Fuse 7. The affected version is set to AFFECTED/DEFER as the CVSS score (5.9) is below the 7.0 threshold for immediate remediation.
Меры по смягчению последствий
No specific mitigation is available. Restrict access to multipart request endpoints where possible.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Fuse 7 | spring-webflux | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
5.9 Medium
CVSS3
Связанные уязвимости
Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests. Affected versions: Spring Framework 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, 5.3.0 through 5.3.48.
Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests. Affected versions: Spring Framework 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, 5.3.0 through 5.3.48.
Spring WebFlux applications are vulnerable to Denial of Service (DoS) ...
Spring Framework Denial of Service via Multipart Requests in WebFlux
EPSS
5.9 Medium
CVSS3