CVE-2023-20863
A flaw was found in Spring Framework. Certain versions of Spring Framework's Expression Language were not restricting the size of Spring Expressions. This could allow an attacker to craft a malicious Spring Expression to cause a denial of service on the server.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability CVE-2023-20863?
CVE-2023-20863 is a flaw in Spring Framework where certain versions of Spring Framework's Expression Language do not restrict the size of Spring Expressions, allowing an attacker to cause a denial of service on the server.
What is the severity of CVE-2023-20863?
The severity of CVE-2023-20863 is medium with a CVSS score of 6.5.
Which versions of Spring Framework are affected by CVE-2023-20863?
Versions of Spring Framework prior to 5.2.24, 5.3.27, and 6.0.8 are affected by CVE-2023-20863.
How can I fix CVE-2023-20863?
To fix CVE-2023-20863, update your Spring Framework to version 5.2.24, 5.3.27, or 6.0.8.
Where can I find more information about CVE-2023-20863?
You can find more information about CVE-2023-20863 at the following references: [CVE-2023-20863](https://www.cve.org/CVERecord?id=CVE-2023-20863), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2023-20863), [Spring Security](https://spring.io/security/cve-2023-20863), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=2187742), [Red Hat Security Advisory](https://access.redhat.com/errata/RHSA-2023:2099).