Improper resource allocation In libspring-java
Description
Allocation of Resources Without Limits or Throttling in Spring Framework In Spring Framework versions 5.3.0 - 5.3.16, 5.2.0.RELEASE - 5.2.19.RELEASE, and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 13 | - | ||
maven | 5.3.17, 5.2.20.release | ||
debian 11 | - | ||
maven | 5.2.20.release, 5.3.17 | ||
debian 14 | - | ||
maven | 5.2.20.release, 5.3.17 | ||
debian 12 | - |
Aliases
1. 2. 3. 4. 5. 6. 7. 8.
References
1. 2. 3. 4. 5. 6.