NA

CVE-2023-34055

Published: 28/11/2023 Updated: 21/12/2023
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

In Spring Boot versions 2.7.0 - 2.7.17, 3.0.0-3.0.12 and 3.1.0-3.1.5, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable when all of the following are true: * the application uses Spring MVC or Spring WebFlux * org.springframework.boot:spring-boot-actuator is on the classpath

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

vmware spring boot

Vendor Advisories

DescriptionThe MITRE CVE dictionary describes this issue as: In Spring Boot versions 270 - 2717, 300-3012 and 310-315, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition Specifically, an application is vulnerable when all of the following are true: * the application u ...