Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40148
HistoryApr 18, 2023 - 7:02 a.m.

Denial Of Service (DoS)

2023-04-1807:02:49
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17
denial of service
dos
spring expression language
vulnerability
internalspelexpressionparser.java
application crash
security

0.003 Low

EPSS

Percentile

70.0%

Spring Expression Language is vulnerable to Denial Of Service (DoS). The vulnerability exists in the doParseExpression function of InternalSpelExpressionParser.java because the SpEL expression length is not restricted which allows an attacker to cause an application crash.