Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreIn Spring Boot, there is potential for a denial-of-service (DoS) attack if Spring MVC is used together with a reverse proxy cache.
Specifically, an application is vulnerable if all of the conditions are true:
Your application is NOT vulnerable if any of the following are true:
WebMvcAutoConfiguration is explicitly excluded, if Spring MVC is not on the classpath, or if spring.main.web-application-type is set to a value other than SERVLET.Spring Boot:
| Fix version | Availability |
|---|---|
| 3.0.7 | OSS |
| 2.7.12 | OSS |
| 2.6.15 | OSS |
| 2.5.15 | OSS |
Workarounds: configure the reverse proxy not to cache 404 responses and/or not to cache responses to requests to the root (/) of the application.
Martin van Kervel Smedshammer
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy