Asymmetric denial of service In org.springframework:spring-webmvc
Description
Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources.
Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
debian 11 | - | ||
debian 12 | - | ||
debian 13 | - | ||
debian 14 | - | ||
maven | 7.0.8, 6.2.19 | ||
maven | 7.0.8, 6.2.19 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3.