Spring Data Commons contains a vulnerability that can lead to a Denial of Service (DoS) condition if Spring Data Web Support is enabled in conjunction with a Controller method using @ProjectedPayload, when an attacker sends a specially crafted HTTP request that causes the application to allocate lots of memory. Affected versions: Spring Data Commons 4.0.0 through 4.0.5; 3.5.0 through 3.5.11; 3.4.0 through 3.4.14; 3.3.0 through 3.3.16; 3.2.0 through 3.2.15; 3.1.0 through 3.1.14; 3.0.0 through 3.0.15; 2.7.0 through 2.7.19.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.7.0, < 2.7.20CPE matchmatch criteria | cpe:2.3:a:broadcom:spring_data_commons:*:*:*:*:*:*:*:* | ||
>= 3.0.0, <= 3.0.15CPE matchmatch criteria | cpe:2.3:a:broadcom:spring_data_commons:*:*:*:*:*:*:*:* | ||
>= 3.1.0, <= 3.1.14CPE matchmatch criteria | cpe:2.3:a:broadcom:spring_data_commons:*:*:*:*:*:*:*:* | ||
>= 3.2.0, <= 3.2.15CPE matchmatch criteria | cpe:2.3:a:broadcom:spring_data_commons:*:*:*:*:*:*:*:* | ||
>= 3.3.0, < 3.3.17CPE matchmatch criteria | cpe:2.3:a:broadcom:spring_data_commons:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.