Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provide a pattern which is then directly or indirectly supplied to one of the following methods in AntPathMatcher: match(String pattern, String path), matchStart(String pattern, String path), extractUriTemplateVariables(String pattern, String path).
Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Spring_framework | Vmware | 5.3.0 (including) | 5.3.49 (excluding) |
| Spring_framework | Vmware | 6.1.0 (including) | 6.1.28 (excluding) |
| Spring_framework | Vmware | 6.2.0 (including) | 6.2.18.1 (excluding) |
| Spring_framework | Vmware | 7.0.0 (including) | 7.0.7.1 (excluding) |
| Libspring-java | Ubuntu | questing | * |