Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
| Vendor | Product | Versions |
|---|---|---|
| vmware | spring_framework | maven/org.springframework:spring-webmvc: >= 7.0.0, <= 7.0.7, maven/org.springframework:spring-webflux: >= 7.0.0, <= 7.0.7, maven/org.springframework:spring-webmvc: >= 6.2.0, <= 6.2.18, maven/org.springframework:spring-webflux: >= 6.2.0, <= 6.2.18, maven/org.springframework:spring-webmvc: >= 6.1.0, <= 6.1.21, maven/org.springframework:spring-webflux: >= 6.1.0, <= 6.1.21, maven/org.springframework:spring-webmvc: <= 5.3.39, maven/org.springframework:spring-webflux: <= 5.3.39 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| maven | org.springframework:spring-webflux | GHSA | 85% |
| maven | org.springframework:spring-webmvc | GHSA | 85% |
| vmware tanzu | spring framework | cert_advisory | 90% |
Updated vendor to Vmware, changed exploit availability to false, and provided a new description with additional details.
Initial creation