CyberRota Analysis
AI-GeneratedApplications utilizing the Spring Framework's data binding feature may be susceptible to Denial of Service (DoS) attacks due to improper handling of user-supplied property paths. This vulnerability affects multiple versions of the Spring Framework, including 5.2.25 and later, up to 7.0.8. Organizations using these affected versions should prioritize remediation to prevent potential service disruptions.
Original NVD Description
Spring Framework applications that use Spring's data binding infrastructure to apply user-supplied property paths onto a target object may be vulnerable to a Denial of Service (DoS) attack. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier
Related CVEs
Other vulnerabilities affecting the same vendor(s)