First published: Thu Apr 13 2023(Updated: )
A flaw was found in Spring Framework. Certain versions of Spring Framework's Expression Language were not restricting the size of Spring Expressions. This could allow an attacker to craft a malicious Spring Expression to cause a denial of service on the server.
Credit: security@vmware.com security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Spring Framework | >=5.2.0<5.2.24 | |
VMware Spring Framework | >=5.3.0<5.3.27 | |
VMware Spring Framework | >=6.0.0<6.0.8 | |
redhat/spring framework | <6.0.8 | 6.0.8 |
redhat/spring framework | <5.3.27 | 5.3.27 |
redhat/spring framework | <5.2.24. | 5.2.24. |
maven/org.springframework:spring-expression | <5.2.24.RELEASE | 5.2.24.RELEASE |
maven/org.springframework:spring-expression | >=5.3.0<5.3.27 | 5.3.27 |
maven/org.springframework:spring-expression | >=6.0.0<6.0.8 | 6.0.8 |
IBM Cloud Pak for Business Automation | <=V22.0.2 - V22.0.2-IF004 | |
IBM Cloud Pak for Business Automation | <=V21.0.3 - V21.0.3-IF020 | |
IBM Cloud Pak for Business Automation | <=V22.0.1 - V22.0.1-IF006 and later fixesV21.0.2 - V21.0.2-IF012 and later fixesV21.0.1 - V21.0.1-IF007 and later fixesV20.0.1 - V20.0.3 and later fixesV19.0.1 - V19.0.3 and later fixesV18.0.0 - V18.0.2 and later fixes |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-20863 is a flaw in Spring Framework where certain versions of Spring Framework's Expression Language do not restrict the size of Spring Expressions, allowing an attacker to cause a denial of service on the server.
The severity of CVE-2023-20863 is medium with a CVSS score of 6.5.
Versions of Spring Framework prior to 5.2.24, 5.3.27, and 6.0.8 are affected by CVE-2023-20863.
To fix CVE-2023-20863, update your Spring Framework to version 5.2.24, 5.3.27, or 6.0.8.
You can find more information about CVE-2023-20863 at the following references: [CVE-2023-20863](https://www.cve.org/CVERecord?id=CVE-2023-20863), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2023-20863), [Spring Security](https://spring.io/security/cve-2023-20863), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=2187742), [Red Hat Security Advisory](https://access.redhat.com/errata/RHSA-2023:2099).