Spring Framework server Web Observations DoS Vulnerability
CVE-2023-34053
What is CVE-2023-34053?
In versions 6.0.0 to 6.0.13 of the Spring Framework, a vulnerability exists that can allow attackers to craft specific HTTP requests, resulting in a denial-of-service (DoS) condition. This issue is present when an application utilizes Spring MVC or Spring WebFlux, includes the io.micrometer:micrometer-core in the classpath, and has an ObservationRegistry configured to record observations. Typically, applications built with Spring Boot require the org.springframework.boot:spring-boot-actuator dependency to satisfy these conditions, thus increasing the risk of service disruption.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Spring Framework Windows 6.0.0 < 6.0.14
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
