Asymmetric denial of service - ReDoS In org.springframework:spring-expression
Description
Spring Framework Denial of Service via Integer Overflow in SpEL Expressions An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker can exploit this by supplying a specially crafted SpEL expression that triggers excessive resource consumption, resulting in a Denial of Service (DoS).
Affected versions: Spring Framework 5.3.0 through 5.3.48.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
debian 13 | - | ||
debian 12 | - | ||
debian 14 | - | ||
debian 11 | - | ||
maven | 6.0.0 |
Aliases
1. 2. 3. 4. 5. 6.
References
1.