PT-2024-7271 · Spring+1 · Spring Framework+1

Popko

·

Published

2024-08-14

·

Updated

2025-02-20

·

CVE-2024-38808

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: Spring Framework versions 5.3.0 through 5.3.38 Spring Framework older unsupported versions
Description: The issue is related to the Spring Expression Language (SpEL) in Spring Framework. It is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service (DoS) condition. An application is vulnerable when it evaluates user-supplied SpEL expressions.
Recommendations: For Spring Framework versions 5.3.0 through 5.3.38, consider upgrading to a newer version to mitigate the risk. For Spring Framework older unsupported versions, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting the evaluation of user-supplied SpEL expressions to minimize the risk of exploitation.

DoS

Allocation of Resources Without Limits

Improper Resource Release

Weakness Enumeration

Related Identifiers

BDU:2024-08623
CVE-2024-38808
GHSA-9CMQ-M9J5-MVWW
RHSA-2024:8884
RHSA-2024:8885
RHSA-2024:8886
RHSA-2024:8887

Affected Products

Debian
Spring Framework