Skip to content

BDSA-2024-5369 for springboot 3.4.0-M3 app #33755

@patpatpat123

Description

@patpatpat123

Hello team,

We run daily security scan tools (blackduck, sonarqube, dependecy check, owasp etc)
They are all flagging this:

{
      "Related Vuln": "",
      "CVE ID": "BDSA-2024-5369",
      "Vulnerability Description": "Spring Framework contains an inefficient regular expression for its handling of Etags. If an application parses ETags from \"If-Match\" or \"If-None-Match\" request headers, a remote attacker could cause a denial-of-service (DoS).",
      "Package Name": "Spring Framework",
      "Package Version": "6.2.0-RC1",
      "Status": "NEW",
      "Vulnerability Published Date": "2024-08-15",
      "Upgrade-Guidance": {
         "Short-Term": "6.1.14",
         "Long-Term": "6.1.14"
      },

This is for a latest (as of this writing spring boot 3.4.0-M3 app.

Could you please help take a look at this, and fix the CVE?

Thank you for your kind help

Metadata

Metadata

Assignees

No one assigned

    Labels

    status: invalidAn issue that we don't feel is valid

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions