In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.springframework:spring-messaging(Maven) | 5.3.0 | 5.3.20 | N/A |
| org.springframework:spring-messaging(Maven) | 0 | 5.2.22.RELEASE | N/A |
CVSS Metrics