In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial of service (DoS) condition.
Specifically, an application is vulnerable when the following is true:
{
"cna_assigner": "vmware",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/38xxx/CVE-2024-38808.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "5.3.0"
},
{
"fixed": "5.3.39, 6.0+"
}
],
"source": "AFFECTED_FIELD"
}
]
}