Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39962
HistoryMar 27, 2023 - 10:04 p.m.

Denial Of Service (DoS)

2023-03-2722:04:35
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12
denial of service
spring framework
vulnerability
expression language
parser
cpu memory
system crash

0.001 Low

EPSS

Percentile

48.7%

Spring Framework is vulnerable to Denial of Service (DoS). The vulnerability is due to a lack of max repeated words and max number of character logic in the Spring Expression Language parser located in the getValueInternal function of OpMultiply and the getValueInternal function in OperatorMatches, which can trigger an infinite loop and consume excessive CPU memory, possibly leading to a system crash.