CVE-2023-20861
published 2023-03-23CVE-2023-20861: In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versions, it is possible for a user to…
PriorityP430medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.97%
58.0th percentile
In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libspring-java | — | — |
| vmware | spring_framework | <= 5.2.22 | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | 5.3.0 – 5.3.25 | — |
| vmware | spring_framework | 6.0.0 – 6.0.6 | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_debian6.5LOW
vendor_oracle6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-20861: In Spring Framework versions 6
osv·2023-03-23·CVSS 6.5
CVE-2023-20861 [MEDIUM] CVE-2023-20861: In Spring Framework versions 6
In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.
GHSA
Spring Framework vulnerable to denial of service via specially crafted SpEL expression
ghsa·2023-03-23
CVE-2023-20861 [MEDIUM] CWE-400 Spring Framework vulnerable to denial of service via specially crafted SpEL expression
Spring Framework vulnerable to denial of service via specially crafted SpEL expression
In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.
OSV
Spring Framework vulnerable to denial of service via specially crafted SpEL expression
osv·2023-03-23
CVE-2023-20861 [MEDIUM] Spring Framework vulnerable to denial of service via specially crafted SpEL expression
Spring Framework vulnerable to denial of service via specially crafted SpEL expression
In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Install (Spring Framework) — CVE-2023-20861
vendor_oracle·2024-04-15·CVSS 6.5
CVE-2023-20861 [MEDIUM] Oracle Oracle Enterprise Manager Risk Matrix: Install (Spring Framework) — CVE-2023-20861
Oracle Oracle Enterprise Manager Risk Matrix: Install (Spring Framework) vulnerability
CVE: CVE-2023-20861
CVSS: 6.5
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuapr2024 (APR 2024)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Core (Spring Boot) — CVE-2023-20861
vendor_oracle·2023-07-15·CVSS 6.5
CVE-2023-20861 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Core (Spring Boot) — CVE-2023-20861
Oracle Oracle Communications Applications Risk Matrix: Core (Spring Boot) vulnerability
CVE: CVE-2023-20861
CVSS: 6.5
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Red Hat
springframework: Spring Expression DoS Vulnerability
vendor_redhat·2023-03-20·CVSS 6.5
CVE-2023-20861 [MEDIUM] CWE-770 springframework: Spring Expression DoS Vulnerability
springframework: Spring Expression DoS Vulnerability
In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.
A flaw found was found in Spring Framework. This flaw allows a malicious user to use a specially crafted SpEL expression that causes a denial of service (DoS).
Package: springframework (A-MQ Clients 2) - Not affected
Package: openshift-logging/elasticsearch6-rhel8 (Logging Subsystem for Red Hat OpenShift) - Not affected
Package: org.keycloak-keycloak-parent (Migration Toolkit for Applications 6) - Not affected
Package: org.keycloak-keycloak-parent (Migration Toolkit for Runtimes) - Not a
Debian
CVE-2023-20861: libspring-java - In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2....
vendor_debian·2023·CVSS 6.5
CVE-2023-20861 [MEDIUM] CVE-2023-20861: libspring-java - In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2....
In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-03-23
Published