GHSA-w3c8-7r8f-9jp8

Suggest an improvement
Source
https://github.com/advisories/GHSA-w3c8-7r8f-9jp8
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/11/GHSA-w3c8-7r8f-9jp8/GHSA-w3c8-7r8f-9jp8.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-w3c8-7r8f-9jp8
Aliases
Published
2024-11-18T06:30:35Z
Modified
2025-01-11T00:39:23.012260Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
Spring MVC controller vulnerable to a DoS attack
Details

Spring MVC controller methods with an @RequestBody byte[] method parameter are vulnerable to a DoS attack.

Database specific
{
    "nvd_published_at": "2024-11-18T04:15:04Z",
    "cwe_ids": [],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2024-11-18T20:05:11Z"
}
References

Affected packages

Maven / org.springframework:spring-webmvc

Package

Name
org.springframework:spring-webmvc
View open source insights on deps.dev
Purl
pkg:maven/org.springframework/spring-webmvc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.3.0
Fixed
5.3.42

Affected versions

5.*

5.3.0
5.3.1
5.3.2
5.3.3
5.3.4
5.3.5
5.3.6
5.3.7
5.3.8
5.3.9
5.3.10
5.3.11
5.3.12
5.3.13
5.3.14
5.3.15
5.3.16
5.3.17
5.3.18
5.3.19
5.3.20
5.3.21
5.3.22
5.3.23
5.3.24
5.3.25
5.3.26
5.3.27
5.3.28
5.3.29
5.3.30
5.3.31
5.3.32
5.3.33
5.3.34
5.3.35
5.3.36
5.3.37
5.3.38
5.3.39