๐Ÿ” CVE Alert

CVE-2023-20883

HIGH 7.5
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

In Spring Boot versions 3.0.0 - 3.0.6, 2.7.0 - 2.7.11, 2.6.0 - 2.6.14, 2.5.0 - 2.5.14 and older unsupported versions, there is potential for a denial-of-service (DoS) attack if Spring MVC is used together with a reverse proxy cache.

CWE CWE-400
Vendor n/a
Product spring boot
Ecosystems
Industries
TechnologyEnterprise
Published May 26, 2023
Last Updated Jan 16, 2025
Stay Ahead of the Next One

Get instant alerts for n/a spring boot

Be the first to know when new high vulnerabilities affecting n/a spring boot are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

n/a / Spring Boot
Spring Boot versions 3.0.0 - 3.0.6, 2.7.0 - 2.7.11, 2.6.0 - 2.6.14, 2.5.0 - 2.5.14 and older unsupported versions

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
spring.io: https://spring.io/security/cve-2023-20883 security.netapp.com: https://security.netapp.com/advisory/ntap-20230703-0008/