CVE-2024-38809
Data: 2024-08-28
Severity: High
CVSS Score: 8.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N)
Riferimenti:
Libreria: org.springframework:spring-web <= 5.3.38
Descrizione
CWE-1333
Spring Framework - Regular expression Denial of Service (ReDoS)
Spring Framework DoS via conditional HTTP request
Applications that parse ETags from «If-Match» or «If-None-Match» request headers are vulnerable to DoS attack.
GovWay
Versione affette: <= 3.3.15
Risoluzione: 3.3.15.p1