Описание
An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker can exploit this by supplying a specially crafted SpEL expression that triggers excessive resource consumption, resulting in a Denial of Service (DoS).
Affected versions:
Spring Framework 5.3.0 through 5.3.48.
A flaw was found in the Spring Expression Language (SpEL) within the Spring Framework. An integer overflow vulnerability allows a remote attacker to supply a specially crafted SpEL expression. This can trigger excessive resource consumption, leading to a Denial of Service (DoS) condition.
Отчет
A flaw was found in Spring Framework. An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker can exploit this by supplying a specially crafted SpEL expression that triggers excessive resource consumption, resulting in a Denial of Service (DoS). This vulnerability only affects Spring Framework 5.3.48 and earlier versions. The 6.x branch is not affected. Example:
In order to be exploitable, an application is required to accept and evaluate untrusted (user-controlled) SpEL expressions. Thus AC:H.
Меры по смягчению последствий
Applications that don't evaluate user-controlled SpEL expressions are not affected. Users of affected versions should upgrade to the corresponding fixed version.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| OpenShift Developer Tools and Services | spring-expression | Not affected | ||
| Red Hat OpenShift Dev Spaces | spring-expression | Not affected |
Показывать по
Дополнительная информация
Статус:
5.9 Medium
CVSS3
Связанные уязвимости
An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker can exploit this by supplying a specially crafted SpEL expression that triggers excessive resource consumption, resulting in a Denial of Service (DoS). Affected versions: Spring Framework 5.3.0 through 5.3.48.
An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker can exploit this by supplying a specially crafted SpEL expression that triggers excessive resource consumption, resulting in a Denial of Service (DoS). Affected versions: Spring Framework 5.3.0 through 5.3.48.
An integer overflow vulnerability exists in the evaluation logic of th ...
An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker can exploit this by supplying a specially crafted SpEL expression that triggers excessive resource consumption, resulting in a Denial of Service (DoS). Affected versions: Spring Framework 5.3.0 through 5.3.48.
5.9 Medium
CVSS3