Lucene search

K
osvGoogleOSV:GHSA-RQPH-VQWM-22VC
HistoryMay 13, 2022 - 12:00 a.m.

Allocation of Resources Without Limits or Throttling in Spring Framework

2022-05-1300:00:29
Google
osv.dev
19
spring framework
stomp over websocket
denial of service

EPSS

0.002

Percentile

60.3%

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.