Lucene search

K
f5F5F5:K31022653
HistoryMay 24, 2018 - 12:00 a.m.

K31022653 : Spring Framework vulnerability CVE-2018-1257

2018-05-2400:00:00
my.f5.com
21

AI Score

5.5

Confidence

High

EPSS

0.002

Percentile

54.1%

Security Advisory Description

Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a regular expression, denial of service attack. (CVE-2018-1257)

Impact

There is no impact; F5 products are not affected by this vulnerability.

AI Score

5.5

Confidence

High

EPSS

0.002

Percentile

54.1%