veracode-repository-ruleset / verademo-java-maven

verademo-java-maven
0 stars 0 forks source link

CVE: 2023-20863 found in Spring Expression Language (SpEL) - Version: 4.3.10.RELEASE [JAVA] #46

Open github-actions[bot] opened 7 months ago

github-actions[bot] commented 7 months ago

Veracode Software Composition Analysis

Attribute Details
Library Spring Expression Language (SpEL)
Description Spring Expression Language (SpEL)
Language JAVA
Vulnerability Denial Of Service (DoS)
Vulnerability description Spring Expression Language is vulnerable to Denial Of Service (DoS). The vulnerability exists in the doParseExpression function of InternalSpelExpressionParser.java because the SpEL expression length is not restricted which allows an attacker to cause an application crash.
CVE 2023-20863
CVSS score 6.8
Vulnerability present in version/s 4.3.0.RC1-4.3.30.RELEASE
Found library version/s 4.3.10.RELEASE
Vulnerability fixed in version 5.2.24.RELEASE
Library latest version 6.1.1
Fix

Links:

github-actions[bot] commented 4 months ago

Veracode issue link to PR: https://github.com/veracode-repository-ruleset/verademo-java-maven/pull/54