CVE-2024-38809

Data: 2024-08-28

Severity: High

CVSS Score: 8.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N)

Riferimenti:

Libreria: org.springframework:spring-web <= 5.3.38

Descrizione

CWE-1333

Spring Framework - Regular expression Denial of Service (ReDoS)

Spring Framework DoS via conditional HTTP request

Applications that parse ETags from «If-Match» or «If-None-Match» request headers are vulnerable to DoS attack.

GovWay

Versione affette: <= 3.3.15

Risoluzione: 3.3.15.p1