Allocation of Resources Without Limits or Throttling in Spring Framework
Moderate severity
GitHub Reviewed
Published
Apr 3, 2022
to the GitHub Advisory Database
•
Updated Mar 28, 2023
Package
Affected versions
>= 5.3.0, < 5.3.17
< 5.2.20.RELEASE
Patched versions
5.3.17
5.2.20.RELEASE
Description
Published by the National Vulnerability Database
Apr 1, 2022
Published to the GitHub Advisory Database
Apr 3, 2022
Reviewed
Apr 5, 2022
Last updated
Mar 28, 2023
In Spring Framework versions 5.3.0 - 5.3.16, 5.2.0.RELEASE - 5.2.19.RELEASE, and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition.
References