Skip to content

CVE-2023-20863 @ Maven-org.springframework:spring-expression-3.2.8.RELEASE #97

@apcxtest

Description

@apcxtest

Vulnerable Package issue exists @ Maven-org.springframework:spring-expression-3.2.8.RELEASE in branch main

In spring framework in versions through 5.2.23.RELEASE, 5.3.0-M1 through 5.3.26, and 6.0.0-M1 through 6.0.7 it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.

Namespace: apcxtest
Repository: test-repo-pub
Repository Url: https://github.com/apcxtest/test-repo-pub
CxAST-Project: apcxtest/test-repo-pub
CxAST platform scan: a314b9e1-0b75-4c05-86f0-fa4203a6e7fd
Branch: main
Application: test-repo-pub
Severity: HIGH
State: TO_VERIFY
Status: RECURRENT
CWE: CWE-770


Additional Info
Attack vector: NETWORK
Attack complexity: LOW
Confidentiality impact: NONE
Availability impact: HIGH
Remediation Upgrade Recommendation: 5.2.23.RELEASE


References
Advisory
Commit
Issue
Release Note
Advisory

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions