Denial of service in Spring Framework
High severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Mar 14, 2024
Package
Affected versions
<= 5.2.21.RELEASE
>= 5.3.0, < 5.3.20
Patched versions
5.2.22.RELEASE
5.3.20
Description
Published by the National Vulnerability Database
May 12, 2022
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
May 25, 2022
Last updated
Mar 14, 2024
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.
References