Spring Expression Language is vulnerable to Denial Of Service (DoS). The vulnerability exists in the doParseExpression function of InternalSpelExpressionParser.java because the SpEL expression length is not restricted which allows an attacker to cause an application crash.
Veracode Software Composition Analysis
doParseExpression
function ofInternalSpelExpressionParser.java
because the SpEL expression length is not restricted which allows an attacker to cause an application crash.Links: