Lucene search

K
githubGitHub Advisory DatabaseGHSA-WXQC-PXW9-G2P8
HistoryApr 13, 2023 - 9:30 p.m.

Spring Framework vulnerable to denial of service

2023-04-1321:30:27
CWE-400
CWE-770
CWE-917
GitHub Advisory Database
github.com
89
spring framework
vulnerability
denial of service

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

0.003 Low

EPSS

Percentile

70.0%

In Spring Framework versions prior to 5.2.24.release+ , 5.3.27+ and 6.0.8+ , it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial-of-service (DoS) condition.

Affected configurations

Vulners
Node
org.springframework\springMatchexpression
OR
org.springframework\springMatchexpression
OR
org.springframework\springMatchexpression

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

0.003 Low

EPSS

Percentile

70.0%