In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade jenkins | Aug 22, 2024 | May 12, 2022 |
| Debian | — | No solution exists | May 15, 2025 | May 12, 2022 |
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 34686388 for version 14.1.1.0.0.Apply the Patch Set Update (PSU) 34653267 for version 12.2.1.4.0.Apply the Patch Set Update (PSU) 34697822 for version 12.2.1.3.0. | Jan 17, 2023 | May 12, 2022 |
| Zimbra Collaboration | — | Upgrade Zimbra Collaboration to the latest version | Feb 26, 2025 | May 12, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub