Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and older unsupported versions on the 4.2.x branch provide support for range requests when serving static resources through the ResourceHttpRequestHandler, or starting in 5.0 when an annotated controller returns an org.springframework.core.io.Resource. A malicious user (or attacker) can add a range header with a high number of ranges, or with wide ranges that overlap, or both, for a denial of service attack. This vulnerability affects applications that depend on either spring-webmvc or spring-webflux. Such applications must also have a registration for serving static resources (e.g. JS, CSS, images, and others), or have an annotated controller that returns an org.springframework.core.io.Resource. Spring Boot applications that depend on spring-boot-starter-web or spring-boot-starter-webflux are ready to serve static resources out of the box and are therefore vulnerable.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Debian
Subscribe
|
Debian Linux
Subscribe
|
|
Oracle
Subscribe
|
Agile Plm
Subscribe
Communications Brm - Elastic Charging Engine
Subscribe
Communications Converged Application Server - Service Controller
Subscribe
Communications Diameter Signaling Router
Subscribe
Communications Element Manager
Subscribe
Communications Online Mediation Controller
Subscribe
Communications Session Report Manager
Subscribe
Communications Session Route Manager
Subscribe
Communications Unified Inventory Management
Subscribe
Endeca Information Discovery Integrator
Subscribe
Enterprise Manager For Fusion Applications
Subscribe
Enterprise Manager Ops Center
Subscribe
Financial Services Analytical Applications Infrastructure
Subscribe
Flexcube Private Banking
Subscribe
Goldengate Application Adapters
Subscribe
Healthcare Master Person Index
Subscribe
Identity Manager Connector
Subscribe
Insurance Calculation Engine
Subscribe
Insurance Policy Administration J2ee
Subscribe
Insurance Rules Palette
Subscribe
Mysql Enterprise Monitor
Subscribe
Primavera Analytics
Subscribe
Primavera Gateway
Subscribe
Rapid Planning
Subscribe
Retail Advanced Inventory Planning
Subscribe
Retail Assortment Planning
Subscribe
Retail Clearance Optimization Engine
Subscribe
Retail Financial Integration
Subscribe
Retail Integration Bus
Subscribe
Retail Invoice Matching
Subscribe
Retail Markdown Optimization
Subscribe
Retail Order Broker
Subscribe
Retail Predictive Application Server
Subscribe
Retail Service Backbone
Subscribe
Retail Xstore Point Of Service
Subscribe
Tape Library Acsls
Subscribe
Webcenter Sites
Subscribe
Weblogic Server
Subscribe
|
|
Redhat
Subscribe
|
|
|
Vmware
Subscribe
|
Spring Framework
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2635-1 | libspring-java security update |
Github GHSA |
GHSA-ffvq-7w96-97p7 | Denial of Service in Spring Framework |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2024-09-16T16:59:11.041Z
Reserved: 2018-08-23T00:00:00
Link: CVE-2018-15756
No data.
Status : Modified
Published: 2018-10-18T22:29:00.443
Modified: 2024-11-21T03:51:24.640
Link: CVE-2018-15756
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Github GHSA