Lucene search

K
cvelistVmwareCVELIST:CVE-2024-22271
HistoryJul 09, 2024 - 12:50 p.m.

CVE-2024-22271 Spring Cloud Function Web DOS Vulnerability

2024-07-0912:50:15
vmware
www.cve.org
2
spring cloud function
vulnerability
dos attack
web module
version 4.1.2
version 4.0.8
cve-2024-22271

CVSS3

8.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

EPSS

0.001

Percentile

38.7%

In Spring Cloud Function framework, versions 4.1.x prior to 4.1.2, 4.0.x prior to 4.0.8 an application is vulnerable to a DOS attack when attempting to compose functions with non-existing functions.

Specifically, an application is vulnerable when all of the following are true:

User is using Spring Cloud Function Web module

Affected Spring Products and Versions Spring Cloud Function Framework 4.1.0 to 4.1.2 4.0.0 to 4.0.8

References https://spring.io/security/cve-2022-22979 Β  https://checkmarx.com/blog/spring-function-cloud-dos-cve-2022-22979-and-unintended-function-invocation/ Β History 2020-01-16: Initial vulnerability report published.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Spring Cloud Function Framework",
    "vendor": "Spring by VMware Tanzu",
    "versions": [
      {
        "status": "affected",
        "version": "Spring Cloud Function Framework 4.1.0-4.1.2, Spring Cloud Function Framework 4.0.0-4.0.8"
      }
    ]
  }
]

CVSS3

8.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

EPSS

0.001

Percentile

38.7%