VDB
Sign up
MEDIUM5.3

GHSA-2rmj-mq67-h97g

Spring Framework DoS via conditional HTTP request

Quick fix

GHSA-2rmj-mq67-h97g — org.springframework:spring-web: upgrade to the fixed version with the command below.

# pom.xml: bump <version>5.3.38</version> for org.springframework:spring-web

Details

### Description Applications that parse ETags from `If-Match` or `If-None-Match` request headers are vulnerable to DoS attack.

### Affected Spring Products and Versions org.springframework:spring-web in versions

6.1.0 through 6.1.11 6.0.0 through 6.0.22 5.3.0 through 5.3.37

Older, unsupported versions are also affected

### Mitigation Users of affected versions should upgrade to the corresponding fixed version. 6.1.x -> 6.1.12 6.0.x -> 6.0.23 5.3.x -> 5.3.38 No other mitigation steps are necessary.

Users of older, unsupported versions could enforce a size limit on `If-Match` and `If-None-Match` headers, e.g. through a Filter.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.springframework:spring-web
Introduced in: 0Fixed in: 5.3.38
Fix# pom.xml: bump <version>5.3.38</version> for org.springframework:spring-web
Maven/org.springframework:spring-web
Introduced in: 6.0.0Fixed in: 6.0.23
Fix# pom.xml: bump <version>6.0.23</version> for org.springframework:spring-web
Maven/org.springframework:spring-web
Introduced in: 6.1.0Fixed in: 6.1.12
Fix# pom.xml: bump <version>6.1.12</version> for org.springframework:spring-web

References