CVE-2024-22233

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/01/2024
Last modified:
20/06/2025

Description

In Spring Framework versions 6.0.15 and 6.1.2, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition.<br /> <br /> Specifically, an application is vulnerable when all of the following are true:<br /> <br /> * the application uses Spring MVC<br /> * Spring Security 6.1.6+ or 6.2.1+ is on the classpath<br /> <br /> <br /> Typically, Spring Boot applications need the org.springframework.boot:spring-boot-starter-web and org.springframework.boot:spring-boot-starter-security dependencies to meet all conditions.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vmware:spring_framework:6.0.15:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:6.1.2:*:*:*:*:*:*:*