Applications that parse ETags from "If-Match" or "If-None-Match" request headers are vulnerable to DoS attack. Users of affected versions should upgrade to the corresponding fixed version. Users of older, unsupported versions could enforce a size limit on "If-Match" and "If-None-Match" headers, e.g. through a Filter.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.springframework:spring-web(Maven) | 0 | 5.3.38 | N/A |
| org.springframework:spring-web(Maven) | 6.0.0 | 6.0.23 | N/A |
| org.springframework:spring-web(Maven) | 6.1.0 | 6.1.12 | N/A |
CVSS Metrics