Spring Framework vulnerable to denial of service
High severity
GitHub Reviewed
Published
Apr 13, 2023
to the GitHub Advisory Database
•
Updated Jun 10, 2024
Package
Affected versions
>= 6.0.0, < 6.0.8
>= 5.3.0, < 5.3.27
< 5.2.24.RELEASE
Patched versions
6.0.8
5.3.27
5.2.24.RELEASE
Description
Published by the National Vulnerability Database
Apr 13, 2023
Published to the GitHub Advisory Database
Apr 13, 2023
Reviewed
Apr 17, 2023
Last updated
Jun 10, 2024
In Spring Framework versions prior to 5.2.24.release+ , 5.3.27+ and 6.0.8+ , it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial-of-service (DoS) condition.
References