CVE-2023-20863: High severity vmware spring framework vulnerability
A flaw was found in Spring Framework. Certain versions of Spring Framework's Expression Language were not restricting the size of Spring Expressions. This could allow an attacker to craft a malicious Spring Expression to cause a denial of service on the server.
Other sources
In Spring Framework versions 6.0.0 - 6.0.7, 5.3.0 - 5.3.26, 5.2.0.RELEASE - 5.2.23.RELEASE, and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.
— Red Hat
In spring framework versions prior to 5.2.24 release+ ,5.3.27+ and 6.0.8+ , it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.
In Spring Framework versions prior to 5.2.24.release+ , 5.3.27+ and 6.0.8+ , it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial-of-service (DoS) condition.
— GitHub
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability CVE-2023-20863?
CVE-2023-20863 is a flaw in Spring Framework where certain versions of Spring Framework's Expression Language do not restrict the size of Spring Expressions, allowing an attacker to cause a denial of service on the server.
What is the severity of CVE-2023-20863?
The severity of CVE-2023-20863 is medium with a CVSS score of 6.5.
Which versions of Spring Framework are affected by CVE-2023-20863?
Versions of Spring Framework prior to 5.2.24, 5.3.27, and 6.0.8 are affected by CVE-2023-20863.
How can I fix CVE-2023-20863?
To fix CVE-2023-20863, update your Spring Framework to version 5.2.24, 5.3.27, or 6.0.8.
Where can I find more information about CVE-2023-20863?
You can find more information about CVE-2023-20863 at the following references: [CVE-2023-20863](https://www.cve.org/CVERecord?id=CVE-2023-20863), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2023-20863), [Spring Security](https://spring.io/security/cve-2023-20863), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=2187742), [Red Hat Security Advisory](https://access.redhat.com/errata/RHSA-2023:2099).