Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack if the evaluation of a SpEL expression triggers unbounded cache growth. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
| Vendor | Product | Versions |
|---|---|---|
| vmware | spring_framework | maven/org.springframework:spring-expression: >= 7.0.0, <= 7.0.7, maven/org.springframework:spring-expression: >= 6.2.0, <= 6.2.18, maven/org.springframework:spring-expression: >= 6.1.0, <= 6.1.21, maven/org.springframework:spring-expression: <= 5.3.39 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| atlassian | bamboo | cert_advisory | 90% |
| atlassian | bitbucket | cert_advisory | 90% |
| atlassian | fisheye | cert_advisory | 90% |
| atlassian | confluence | cert_advisory | 90% |
| atlassian | crucible | cert_advisory | 90% |
Updated vendor to VMware, changed severity to HIGH, and noted that there is no exploit available.
Initial creation