Denial-of-Service Vulnerability in Spring Framework Products by VMware
CVE-2023-20861

6.5MEDIUM

Key Information:

Vendor
Vmware
Vendor
CVE Published:
23 March 2023

Summary

In various versions of the Spring Framework, including versions 6.0.0 to 6.0.6, 5.3.0 to 5.3.25, and 5.2.0.RELEASE to 5.2.22.RELEASE, a vulnerability exists that allows attackers to submit specially crafted SpEL (Spring Expression Language) expressions. These expressions can potentially lead to a denial-of-service (DoS) condition, disrupting the normal function of applications utilizing the affected framework versions. Organizations using these frameworks are encouraged to review their implementations and apply any necessary updates to mitigate this vulnerability.

Affected Version(s)

Spring Framework Spring Framework (6.0.0 to 6.0.6, 5.3.0 to 5.3.25, 5.2.0.RELEASE to 5.2.22.RELEASE, Older unsupported versions are also affected)

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.