CVE-2023-20861: Medium severity ibm watson knowledge catalog vulnerability
A flaw found was found in Spring Framework. This flaw allows a malicious user to use a specially crafted SpEL expression that causes a denial of service (DoS).
Other sources
In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.
VMware Tanzu Spring Framework is vulnerable to a denial of service. By sending a specially crafted SpEL expression, a remote attacker could exploit this vulnerability to cause a denial of service.
— IBM
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2023-20861?
CVE-2023-20861 is a vulnerability found in Spring Framework that allows a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.
Which versions of Spring Framework are affected?
Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versions are affected.
How can a malicious user exploit this vulnerability?
A malicious user can exploit this vulnerability by providing a specially crafted SpEL expression.
What is the severity of CVE-2023-20861?
The severity of CVE-2023-20861 is medium, with a severity value of 5.3.
How can I fix CVE-2023-20861?
To fix CVE-2023-20861, update to Spring Framework versions 6.0.7, 5.3.26, or apply the recommended patches provided by your vendor.