In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Spring_framework | Vmware | * | 5.2.22 (including) |
Spring_framework | Vmware | 5.3.0 (including) | 5.3.25 (including) |
Spring_framework | Vmware | 6.0.0 (including) | 6.0.6 (including) |
AMQ Broker 7.10.3 | RedHat | springframework | * |
OCP-Tools-4.12-RHEL-8 | RedHat | jenkins-0:2.401.1.1686649641-3.el8 | * |
OCP-Tools-4.12-RHEL-8 | RedHat | jenkins-0:2.426.3.1706515686-3.el8 | * |
OCP-Tools-4.13-RHEL-8 | RedHat | jenkins-0:2.401.1.1686680404-3.el8 | * |
Red Hat Fuse 7.12 | RedHat | springframework | * |
Red Hat support for Spring Boot 2.7.13 | RedHat | springframework | * |
Red Hat Virtualization Engine 4.4 | RedHat | ovirt-dependencies-0:4.5.3-1.el8ev | * |
RHINT Camel-Springboot 3.20.1 | RedHat | springframework | * |
RHPAM 7.13.4 async | RedHat | * | |
Libspring-java | Ubuntu | bionic | * |
Libspring-java | Ubuntu | kinetic | * |
Libspring-java | Ubuntu | lunar | * |
Libspring-java | Ubuntu | mantic | * |
Libspring-java | Ubuntu | trusty | * |
Libspring-java | Ubuntu | trusty/esm | * |
Libspring-java | Ubuntu | xenial | * |