spring-webmvc-6.2.1.jar: 1 vulnerabilities (highest severity is: 5.3) #10080
Labels
assessment
Pull requests that affect the corresponding module
Mend: dependency security vulnerability
Security vulnerability detected by Mend
programming
Pull requests that affect the corresponding module
Vulnerable Library - spring-webmvc-6.2.1.jar
Spring Web MVC
Library home page: https://github.com/spring-projects/spring-framework
Path to dependency file: /build.gradle
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.springframework/spring-webmvc/6.2.1/44bdf7e5641d44044ac52d7bb5c1fc46004e7754/spring-webmvc-6.2.1.jar
Found in HEAD commit: c9f0c0df3aeb15b9978bd7f10ac66a7913f5a284
Vulnerabilities
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
CVE-2024-38828
Vulnerable Library - spring-webmvc-6.2.1.jar
Spring Web MVC
Library home page: https://github.com/spring-projects/spring-framework
Path to dependency file: /build.gradle
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.springframework/spring-webmvc/6.2.1/44bdf7e5641d44044ac52d7bb5c1fc46004e7754/spring-webmvc-6.2.1.jar
Dependency Hierarchy:
Found in HEAD commit: c9f0c0df3aeb15b9978bd7f10ac66a7913f5a284
Found in base branch: develop
Vulnerability Details
Spring MVC controller methods with an @RequestBody byte[] method parameter are vulnerable to a DoS attack.
Publish Date: 2024-11-18
URL: CVE-2024-38828
CVSS 3 Score Details (5.3)
Base Score Metrics:
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: