Total vulnerabilities in the database
In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial of service (DoS) condition.
Specifically, an application is vulnerable when the following is true:
Software | From | Fixed in |
---|---|---|
![]() |
- | 5.3.39 |
vmware / spring_framework | 5.3.0 | 5.3.39 |