Spring Framework
cpe:2.3:a:springsource:spring_framework:*:*:*:*:*:*:*
- >= 7.0.0, <= 7.0.6
- >= 6.2.0, <= 6.2.17
- >= 6.1.0, <= 6.1.26
- >= 5.3.0, <= 5.3.47
A denial-of-service vulnerability has been identified in Spring MVC and WebFlux applications that serve static resources from the file system on Windows platforms. Under these conditions, an attacker can send malicious requests that are slow to process, keeping HTTP connections active and potentially causing a denial-of-service condition on the application.
Exploitation of this vulnerability can lead to a denial-of-service condition, causing the application to become unresponsive or slow down significantly.
Users of affected versions should upgrade to the fixed version. For Spring Framework 7.0.x, upgrade to 7.0.7; for 6.2.x, upgrade to 6.2.18; for 6.1.x, upgrade to 6.1.27; and for 5.3.x, upgrade to 5.3.48.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.