Back

HIGH

Spring Cloud Function Web DOS Vulnerability

Published Jul 9, 2024

Description

In Spring Cloud Function framework, versions 4.1.x prior to 4.1.2, 4.0.x prior to 4.0.8 an application is vulnerable to a DOS attack when attempting to compose functions with non-existing functions.

Specifically, an application is vulnerable when all of the following are true:

User is using Spring Cloud Function Web module

Affected Spring Products and Versions Spring Cloud Function Framework 4.1.0 to 4.1.2 4.0.0 to 4.0.8

References https://spring.io/security/cve-2022-22979   https://checkmarx.com/blog/spring-function-cloud-dos-cve-2022-22979-and-unintended-function-invocation/  History 2020-01-16: Initial vulnerability report published.

Affected products

Remediation

Red Hat statement

The vulnerability in the Spring Cloud Function framework, which allows an attacker to trigger a cache overflow by attempting to compose functions with nonexisting functions, represents a important severity issue due to its potential to facilitate Denial of Service (DoS) attacks. Such attacks can exploit the cache overflow mechanism to consume excessive computational resources, thereby degrading system performance and rendering the application unavailable to legitimate users.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner vmware
Published Jul 9, 2024
Updated Aug 1, 2024
Reserved Jan 8, 2024
CISA Vulnrichment
Updated Jul 11, 2024
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jul 9, 2024
GHSA-J4R7-P9FP-W3F3