PT-2024-1323 · Spring · Spring Framework+2
0Xlegacyy
+7
·
Published
2024-01-08
·
Updated
2024-06-14
·
CVE-2024-22233
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Spring Framework versions 6.0.15 and 6.1.2
Description
The issue is related to an uncontrolled resource consumption vulnerability in the Spring Framework, which can be exploited by sending specially crafted HTTP requests, potentially leading to a denial-of-service (DoS) condition. This vulnerability affects applications that use Spring MVC and have Spring Security 6.1.6+ or 6.2.1+ on the classpath. Over 35,000 services and approximately 1,064,276 results, mainly distributed in China and the United States, are potentially affected.
Recommendations
For Spring Framework versions 6.0.15 and 6.1.2, consider disabling the vulnerable component or restricting access to the application until a patch is available. As a temporary workaround, restrict the use of
org.springframework.boot:spring-boot-starter-web and org.springframework.boot:spring-boot-starter-security dependencies to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.DoS
Resource Exhaustion
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Spring Framework
Spring Mvc
Spring Security