CVE-2024-38808
published 2024-08-20CVE-2024-38808: In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a specially crafted Spring Expression Language…
PriorityP417medium4.3CVSS 3.1
AVNACLPRNUIRSUCNINAL
EPSS
0.54%
41.6th percentile
In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial of service (DoS) condition. Specifically, an application is vulnerable when the following is true: * The application evaluates user-supplied SpEL expressions.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libspring-java | — | — |
| spring | spring_framework | >= 5.3.0 < 5.3.39, 6.0+ | 5.3.39, 6.0+ |
| vmware | spring_framework | >= 5.3.0 < 5.3.39 | 5.3.39 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
osv4.3MEDIUM
vendor_debian4.3LOW
vendor_oracle4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Retail Applications Risk Matrix: Internal Operations (Spring Framework) — CVE-2024-38808
vendor_oracle·2024-10-15·CVSS 4.3
CVE-2024-38808 [MEDIUM] Oracle Oracle Retail Applications Risk Matrix: Internal Operations (Spring Framework) — CVE-2024-38808
Oracle Oracle Retail Applications Risk Matrix: Internal Operations (Spring Framework) vulnerability
CVE: CVE-2024-38808
CVSS: 4.3
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2024 (OCT 2024)
Red Hat
spring-expression: Denial of service when processing a specially crafted Spring Expression Language expression
vendor_redhat·2024-08-20·CVSS 4.3
CVE-2024-38808 [MEDIUM] CWE-400 spring-expression: Denial of service when processing a specially crafted Spring Expression Language expression
spring-expression: Denial of service when processing a specially crafted Spring Expression Language expression
In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial of service (DoS) condition.
Specifically, an application is vulnerable when the following is true:
* The application evaluates user-supplied SpEL expressions.
A flaw was found in the Spring framework package. A maliciously crafted Spring Expression Language (SePL) may trigger uncontrolled CPU usage, leading to a denial of service in the application consuming it. To be considered vulnerable, one application has to evaluate user-supplied SpEL expressions.
Package: org.springframewo
Debian
CVE-2024-38808: libspring-java - In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it i...
vendor_debian·2024·CVSS 4.3
CVE-2024-38808 [MEDIUM] CVE-2024-38808: libspring-java - In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it i...
In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial of service (DoS) condition. Specifically, an application is vulnerable when the following is true: * The application evaluates user-supplied SpEL expressions.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
GHSA
Spring Framework vulnerable to Denial of Service
ghsa·2024-08-20
CVE-2024-38808 [MEDIUM] CWE-770 Spring Framework vulnerable to Denial of Service
Spring Framework vulnerable to Denial of Service
In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial of service (DoS) condition. Older, unsupported versions are also affected.
Specifically, an application is vulnerable when the following is true:
* The application evaluates user-supplied SpEL expressions.
OSV
Spring Framework vulnerable to Denial of Service
osv·2024-08-20
CVE-2024-38808 [MEDIUM] Spring Framework vulnerable to Denial of Service
Spring Framework vulnerable to Denial of Service
In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial of service (DoS) condition. Older, unsupported versions are also affected.
Specifically, an application is vulnerable when the following is true:
* The application evaluates user-supplied SpEL expressions.
OSV
CVE-2024-38808: In Spring Framework versions 5
osv·2024-08-20·CVSS 4.3
CVE-2024-38808 [MEDIUM] CVE-2024-38808: In Spring Framework versions 5
In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial of service (DoS) condition. Specifically, an application is vulnerable when the following is true: * The application evaluates user-supplied SpEL expressions.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-08-20
Published