MEDIUM 6.5 Maven

Allocation of Resources Without Limits or Throttling in Spring Framework

GHSA-558x-2xjg-6232 · CVE-2022-22950

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

In Spring Framework versions 5.3.0 - 5.3.16, 5.2.0.RELEASE - 5.2.19.RELEASE, and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition.

Ready to move

Start Securing

Free, no credit card | First findings in minutes