Spring Cloud Function Web DOS Vulnerability
Published Jul 9, 2024
8.8
HIGHCVSS 4.0
EPSS 0.36%
Description
In Spring Cloud Function framework, versions 4.1.x prior to 4.1.2, 4.0.x prior to 4.0.8 an application is vulnerable to a DOS attack when attempting to compose functions with non-existing functions.
Specifically, an application is vulnerable when all of the following are true:
User is using Spring Cloud Function Web module
Affected Spring Products and Versions Spring Cloud Function Framework 4.1.0 to 4.1.2 4.0.0 to 4.0.8
References https://spring.io/security/cve-2022-22979 https://checkmarx.com/blog/spring-function-cloud-dos-cve-2022-22979-and-unintended-function-invocation/ History 2020-01-16: Initial vulnerability report published.
Affected products
-
- Version Spring Cloud Function Framework 4.1.0-4.1.2, Spring Cloud Function Framework 4.0.0-4.0.8StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Spring by VMware Tanzu | Spring Cloud Function Framework | unaffected |
|
No data.
-
- Version 4.0.0StatusaffectedConstraints<4.0.8
- Version 4.1.0StatusaffectedConstraints<4.1.2
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| VMware | Spring Cloud Function | unaffected |
|
A-MQ Clients 2
org.springframework.cloud/spring-cloud-function-context
Not affected
Red Hat Data Grid 8
org.springframework.cloud/spring-cloud-function-context
Not affected
Red Hat JBoss Data Grid 7
org.springframework.cloud/spring-cloud-function-context
Will not fix
Red Hat JBoss Enterprise Application Platform 7
spring-cloud-function-context
Not affected
Red Hat JBoss Enterprise Application Platform 8
spring-cloud-function-context
Not affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
org.springframework.cloud/spring-cloud-function-context
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| A-MQ Clients 2 | org.springframework.cloud/spring-cloud-function-context | Not affected | n/a |
| Red Hat Data Grid 8 | org.springframework.cloud/spring-cloud-function-context | Not affected | n/a |
| Red Hat JBoss Data Grid 7 | org.springframework.cloud/spring-cloud-function-context | Will not fix | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | spring-cloud-function-context | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | spring-cloud-function-context | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | org.springframework.cloud/spring-cloud-function-context | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The vulnerability in the Spring Cloud Function framework, which allows an attacker to trigger a cache overflow by attempting to compose functions with nonexisting functions, represents a important severity issue due to its potential to facilitate Denial of Service (DoS) attacks. Such attacks can exploit the cache overflow mechanism to consume excessive computational resources, thereby degrading system performance and rendering the application unavailable to legitimate users.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (9)
- https://access.redhat.com/security/cve/CVE-2024-22271 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2296608 Issue Tracking
- https://github.com/advisories/GHSA-j4r7-p9fp-w3f3 Advisory
- https://github.com/spring-cloud/spring-cloud-function/commit/59fe298b67fcb9249db727a7b3a33612fc7a9f75
- https://github.com/spring-cloud/spring-cloud-function/issues/1139
- https://github.com/spring-cloud/spring-cloud-function/releases/tag/v4.1.2
- https://nvd.nist.gov/vuln/detail/CVE-2024-22271
- https://spring.io/security/cve-2024-22271
- https://www.cve.org/CVERecord?id=CVE-2024-22271
Change history (0)
No recorded changes yet.