CVE Vulnerabilities

CVE-2023-20861

Published: Mar 23, 2023 | Modified: Feb 25, 2025
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.

Affected Software

NameVendorStart VersionEnd Version
Spring_frameworkVmware*5.2.22 (including)
Spring_frameworkVmware5.3.0 (including)5.3.25 (including)
Spring_frameworkVmware6.0.0 (including)6.0.6 (including)
AMQ Broker 7.10.3RedHat*
OCP-Tools-4.12-RHEL-8RedHatjenkins-0:2.401.1.1686649641-3.el8*
OCP-Tools-4.12-RHEL-8RedHatjenkins-0:2.426.3.1706515686-3.el8*
OCP-Tools-4.13-RHEL-8RedHatjenkins-0:2.401.1.1686680404-3.el8*
Red Hat Fuse 7.12RedHatspringframework*
Red Hat support for Spring Boot 2.7.13RedHatspringframework*
Red Hat Virtualization Engine 4.4RedHatovirt-dependencies-0:4.5.3-1.el8ev*
RHINT Camel-Springboot 3.20.1RedHatspringframework*
RHPAM 7.13.4 asyncRedHat*
Libspring-javaUbuntubionic*
Libspring-javaUbuntufocal*
Libspring-javaUbuntukinetic*
Libspring-javaUbuntulunar*
Libspring-javaUbuntumantic*
Libspring-javaUbuntuoracular*
Libspring-javaUbuntuplucky*
Libspring-javaUbuntutrusty*
Libspring-javaUbuntutrusty/esm*
Libspring-javaUbuntuxenial*

References