All vulnerabilities
CVE-2023-34055
Spring Boot Actuator denial of service vulnerability
Description
In Spring Boot versions 2.7.0 - 2.7.17, 3.0.0-3.0.12 and 3.1.0-3.1.5, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition.
Specifically, an application is vulnerable when all of the following are true:
- the application uses Spring MVC or Spring WebFlux
org.springframework.boot:spring-boot-actuatoris on the classpath
Patch Available
Fix available through Seal Security.
No upgrade required, protect your application instantly.
Fix without upgrading
Score
Severity
Ecosystem
Java
Publish Date
November 28, 2023
Modified Date
February 13, 2025
Score Vector
Affected Versions

