Allocation of Resources Without Limits or Throttling in Spring Framework
Moderate severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Mar 14, 2024
Package
Affected versions
>= 5.3.0, < 5.3.20
<= 5.2.21.RELEASE
Patched versions
5.3.20
5.2.22.RELEASE
Description
Published by the National Vulnerability Database
May 12, 2022
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
May 24, 2022
Last updated
Mar 14, 2024
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.
References