Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreIn Spring Framework, it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial of service (DoS) condition.
Specifically, an application is vulnerable when the following is true:
Spring Framework:
| Fix version | Availability |
|---|---|
| 5.3.39 | OSS |
Evaluation of user-supplied SpEL expressions should be avoided when possible; otherwise, user-supplied SpEL expressions should be evaluated with a SimpleEvaluationContext in read-only mode. No other steps are necessary.
This issue was identified and responsibly reported by popko.
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy