Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreSpring MVC controller methods with an @RequestBody byte[]
method parameter are vulnerable to a DoS attack.
Spring Framework:
Users of affected versions should upgrade to the corresponding fixed version.
Affected version(s) | Fix version | Availability |
---|---|---|
5.3.x | 5.3.42 | Commercial |
No further mitigation steps are necessary.
In older, unsupported versions, an application could declare an InputStream method parameter instead to access the request body.
This issues was responsibly reported by macter.
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy