Spring Boot
cpe:2.3:a:pivotal_software:spring_boot:*:*:*:*:*:*:*, +1 more
- >= 4.0.0, <= 4.0.5
- >= 3.5.0, <= 3.5.13
- >= 3.4.0, <= 3.4.15
- >= 3.3.0, <= 3.3.18
- >= 2.7.0, <= 2.7.32
A timing attack vulnerability has been identified in VMware Spring Boot versions 4.0.0 through 4.0.5, 3.5.0 through 3.5.13, 3.4.0 through 3.4.15, 3.3.0 through 3.3.18, and 2.7.0 through 2.7.32. This vulnerability allows an attacker on the same network as the remote application to exploit timing discrepancies to infer information about a remote secret. In severe cases, this could lead to the attacker determining the secret and uploading modified classes, thereby executing remote code in the application.
Exploitation of this vulnerability could result in unauthorized information disclosure followed by remote code execution on the affected application.
Users should upgrade to Spring Boot 4.0.6, 3.5.14, 3.4.16 (Enterprise Support Only), 3.3.19 (Enterprise Support Only) or 2.7.33 (Enterprise Support Only).
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.