Skip to content

CVE: 2023-20883 found in spring-boot-autoconfigure - Version: 2.3.1.RELEASE [JAVA] #150

Description

@Rajkumarr77

Veracode Software Composition Analysis

AttributeDetails
Libraryspring-boot-autoconfigure
DescriptionSpring Boot AutoConfigure
LanguageJAVA
VulnerabilityDenial Of Service (DoS)
Vulnerability descriptionspring-boot-autoconfigure is vulnerable to Denial Of Service (DoS). The vulnerability is applicable when the application has Spring MVC auto-configuration enabled and uses the Spring Boot welcome page, which can be either static or templated, and the application is deployed behind a proxy which caches the 404 responses. An attacker can cause the application to crash by submitting a request to the welcome page which the server is unable to properly respond to.
CVE2023-20883
CVSS score7.1
Vulnerability present in version/s1.4.1.RELEASE-2.5.14
Found library version/s2.3.1.RELEASE
Vulnerability fixed in version2.5.15
Library latest version4.0.0-M1
Fix

Links:

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions