QID 984159

QID 984159: Java (maven) Security Update for org.springframework:spring-core (GHSA-558x-2xjg-6232)

In Spring Framework versions 5.3.0 - 5.3.16, 5.2.0 - 5.2.19, and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 6.2 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to refer to GHSA-558x-2xjg-6232 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 984159

    Software Advisories
    Advisory ID Software Component Link
    GHSA-558x-2xjg-6232 org.springframework:spring-core URL Logo github.com/advisories/GHSA-558x-2xjg-6232