In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.springframework:spring-beans(Maven) | 0 | 5.2.22.RELEASE | N/A |
| org.springframework:spring-beans(Maven) | 5.3.0 | 5.3.20 | N/A |
CVSS Metrics