Asymmetric denial of service - ReDoS In org.springframework:spring-context
Description
Affected versions of the package are vulnerable to Denial of Service (DoS). The CronSequenceGenerator constructor goes into infinite loop if one of the fields is of the form n/0.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version |
|---|---|---|
maven |
Aliases
1.
References
1.