QID 376717

Date Published: 2022-07-06

QID 376717: Spring Cloud Function Denial of Service (DoS) Vulnerability

In Spring Cloud Function it is possible for a user who directly interacts with framework provided lookup functionality to cause denial of service condition due to the caching issue in Function Catalog component of the framework.

Affected Versions:
Spring Cloud Function versions 3.2.5 and prior versions

QID Detection: (Authenticated) - Windows
This QID reads the file generated by Qualys utility Qualys Spring4scanwin Scan Utility for Windows
The QID reads 1st 100000 characters from the generated output file.

QID Detection: (Authenticated) - Linux
This QID reads the file generated by Qualys utility Qualys Spring4scanlinuxScan Utility for Linux to find vulnerable instances of Spring Cloud Function.

Successful exploitation could lead to denial of service attack

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    The vendor has released an advisory to resolve these issues.

    Customers are advised to visit Spring Cloud Function Dos Vulnerability for more information on this.

    Vendor References

    CVEs related to QID 376717

    Software Advisories
    Advisory ID Software Component Link
    Spring Cloud Function URL Logo tanzu.vmware.com/security/cve-2022-22979