CVE-2024-22271
HIGH8.2EPSS 0.29%Spring Cloud Function Framework vulnerable to Denial of Service
Published: 7/9/2024Modified: 7/9/2024
Description
In Spring Cloud Function framework, versions 4.1.x prior to 4.1.2, 4.0.x prior to 4.0.8 an application is vulnerable to a DOS attack when attempting to compose functions with non-existing functions. Specifically, an application is vulnerable when all of the following are true: User is using Spring Cloud Function Web module Affected Spring Products and Versions Spring Cloud Function Framework 4.1.0 to 4.1.2 4.0.0 to 4.0.8 References https://spring.io/security/cve-2022-22979 https://checkmarx.com/blog/spring-function-cloud-dos-cve-2022-22979-and-unintended-function-invocation/ History 2020-01-16: Initial vulnerability report published.
Affected packages (1)
- Maven/org.springframework.cloud:spring-cloud-function-context>= 4.0.0, < 4.0.8
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N |
| osv | CVSS 3.1 | HIGH8.2 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H |
References (6)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2024-22271
- PATCHhttps://github.com/spring-cloud/spring-cloud-function
- WEBhttps://github.com/spring-cloud/spring-cloud-function/commit/59fe298b67fcb9249db727a7b3a33612fc7a9f75
- WEBhttps://github.com/spring-cloud/spring-cloud-function/issues/1139
- WEBhttps://github.com/spring-cloud/spring-cloud-function/releases/tag/v4.1.2
- WEBhttps://spring.io/security/cve-2024-22271