HIGH 7.5 Maven

Spring Framework vulnerable to denial of service

GHSA-wxqc-pxw9-g2p8 · CVE-2023-20863

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

In Spring Framework versions prior to 5.2.24.release+ , 5.3.27+ and 6.0.8+ , it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial-of-service (DoS) condition.

Ready to move

Start Securing

Free, no credit card | First findings in minutes