PT-2024-1323 · Spring · Spring Framework+2

0Xlegacyy

+7

·

Published

2024-01-08

·

Updated

2024-06-14

·

CVE-2024-22233

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Spring Framework versions 6.0.15 and 6.1.2
Description The issue is related to an uncontrolled resource consumption vulnerability in the Spring Framework, which can be exploited by sending specially crafted HTTP requests, potentially leading to a denial-of-service (DoS) condition. This vulnerability affects applications that use Spring MVC and have Spring Security 6.1.6+ or 6.2.1+ on the classpath. Over 35,000 services and approximately 1,064,276 results, mainly distributed in China and the United States, are potentially affected.
Recommendations For Spring Framework versions 6.0.15 and 6.1.2, consider disabling the vulnerable component or restricting access to the application until a patch is available. As a temporary workaround, restrict the use of org.springframework.boot:spring-boot-starter-web and org.springframework.boot:spring-boot-starter-security dependencies to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Resource Exhaustion

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-00777
CVE-2024-22233
GHSA-R4Q3-7G4Q-X89M

Affected Products

Spring Framework
Spring Mvc
Spring Security