GHSA-j4r7-p9fp-w3f3

Suggest an improvement
Source
https://github.com/advisories/GHSA-j4r7-p9fp-w3f3
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/07/GHSA-j4r7-p9fp-w3f3/GHSA-j4r7-p9fp-w3f3.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-j4r7-p9fp-w3f3
Aliases
  • CVE-2024-22271
Published
2024-07-09T15:30:53Z
Modified
2024-07-09T21:42:44.433619Z
Severity
  • 8.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H CVSS Calculator
  • 8.8 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Spring Cloud Function Framework vulnerable to Denial of Service
Details

In Spring Cloud Function framework, versions 4.1.x prior to 4.1.2, 4.0.x prior to 4.0.8 an application is vulnerable to a DOS attack when attempting to compose functions with non-existing functions.

Specifically, an application is vulnerable when all of the following are true:

User is using Spring Cloud Function Web module

Affected Spring Products and Versions Spring Cloud Function Framework 4.1.0 to 4.1.2 4.0.0 to 4.0.8

References https://spring.io/security/cve-2022-22979   https://checkmarx.com/blog/spring-function-cloud-dos-cve-2022-22979-and-unintended-function-invocation/  History 2020-01-16: Initial vulnerability report published.

Database specific
{
    "nvd_published_at": "2024-07-09T13:15:09Z",
    "cwe_ids": [
        "CWE-20"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2024-07-09T21:13:48Z"
}
References

Affected packages

Maven / org.springframework.cloud:spring-cloud-function-context

Package

Name
org.springframework.cloud:spring-cloud-function-context
View open source insights on deps.dev
Purl
pkg:maven/org.springframework.cloud/spring-cloud-function-context

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.0.0
Fixed
4.0.8

Affected versions

4.*

4.0.0
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6

Maven / org.springframework.cloud:spring-cloud-function-context

Package

Name
org.springframework.cloud:spring-cloud-function-context
View open source insights on deps.dev
Purl
pkg:maven/org.springframework.cloud/spring-cloud-function-context

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.1.0
Fixed
4.1.2

Affected versions

4.*

4.1.0
4.1.1