REDHAT-BUG-2314495: Medium severity Spring spring-web vulnerability
Description Applications that parse ETags from If-Match or If-None-Match request headers are vulnerable to DoS attack.
Affected Spring Products and Versions org.springframework:spring-web in versions
6.1.0 through 6.1.11 6.0.0 through 6.0.22 5.3.0 through 5.3.37
Older, unsupported versions are also affected
Mitigation Users of affected versions should upgrade to the corresponding fixed version. 6.1.x -> 6.1.12 6.0.x -> 6.0.23 5.3.x -> 5.3.38 No other mitigation steps are necessary.
Users of older, unsupported versions could enforce a size limit on If-Match and If-None-Match headers, e.g. through a Filter.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
org.springframework:spring-webto a version that resolves this vulnerability.Fixed in 5.3.38 - Upgrade
Upgrade
org.springframework:spring-webto a version that resolves this vulnerability.Fixed in 6.0.23 - Upgrade
Upgrade
org.springframework:spring-webto a version that resolves this vulnerability.Fixed in 6.1.12 - Compensating control
For older, unsupported versions, enforce a size limit on the `If-Match` and `If-None-Match` request headers at a Filter.
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2314495?
The severity of REDHAT-BUG-2314495 is classified as a Denial of Service (DoS) vulnerability.
How do I fix REDHAT-BUG-2314495?
To fix REDHAT-BUG-2314495, it is recommended to update the Spring Web library to the latest patched version.
Which versions are affected by REDHAT-BUG-2314495?
Affected versions of Spring products are 6.1.0 through 6.1.11, 6.0.0 through 6.0.22, and 5.3.0 through 5.3.37.
What is the impact of exploiting REDHAT-BUG-2314495?
Exploiting REDHAT-BUG-2314495 can lead to an application crashing or becoming unresponsive due to excessive resource consumption.
Are older versions of Spring vulnerable to REDHAT-BUG-2314495?
Yes, older and unsupported versions of Spring Web may also be vulnerable to REDHAT-BUG-2314495.