Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:35014
HistoryApr 07, 2022 - 12:06 p.m.

Denial Of Service (DoS)

2022-04-0712:06:55
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
84

0.001 Low

EPSS

Percentile

35.1%

Spring Expression is vulnerable to denial of service. The vulnerability exists due to the creation of large array in a SpEL and sending meaningless error messages to the user which allows an attacker to send crafted SpEL expressions that leads to an out ouf bound error causing an application crash.