PT-2024-7271 · Spring+1 · Spring Framework+1
Popko
·
Published
2024-08-14
·
Updated
2025-02-20
·
CVE-2024-38808
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions:
Spring Framework versions 5.3.0 through 5.3.38
Spring Framework older unsupported versions
Description:
The issue is related to the Spring Expression Language (SpEL) in Spring Framework. It is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service (DoS) condition. An application is vulnerable when it evaluates user-supplied SpEL expressions.
Recommendations:
For Spring Framework versions 5.3.0 through 5.3.38, consider upgrading to a newer version to mitigate the risk.
For Spring Framework older unsupported versions, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, consider restricting the evaluation of user-supplied SpEL expressions to minimize the risk of exploitation.
DoS
Allocation of Resources Without Limits
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Spring Framework