{"id":"GHSA-w3c8-7r8f-9jp8","summary":"Spring MVC controller vulnerable to a DoS attack","details":"Spring MVC controller methods with an @RequestBody byte[] method parameter are vulnerable to a DoS attack.","aliases":["CVE-2024-38828"],"modified":"2025-05-09T21:35:47Z","published":"2024-11-18T06:30:35Z","database_specific":{"github_reviewed_at":"2024-11-18T20:05:11Z","nvd_published_at":"2024-11-18T04:15:04Z","cwe_ids":["CWE-400"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-38828"},{"type":"PACKAGE","url":"https://github.com/spring-projects/spring-framework"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20250509-0009"},{"type":"WEB","url":"https://spring.io/security/cve-2024-38828"}],"affected":[{"package":{"name":"org.springframework:spring-webmvc","ecosystem":"Maven","purl":"pkg:maven/org.springframework/spring-webmvc"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.3.0"},{"fixed":"5.3.42"}]}],"versions":["5.3.0","5.3.1","5.3.10","5.3.11","5.3.12","5.3.13","5.3.14","5.3.15","5.3.16","5.3.17","5.3.18","5.3.19","5.3.2","5.3.20","5.3.21","5.3.22","5.3.23","5.3.24","5.3.25","5.3.26","5.3.27","5.3.28","5.3.29","5.3.3","5.3.30","5.3.31","5.3.32","5.3.33","5.3.34","5.3.35","5.3.36","5.3.37","5.3.38","5.3.39","5.3.4","5.3.5","5.3.6","5.3.7","5.3.8","5.3.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/11/GHSA-w3c8-7r8f-9jp8/GHSA-w3c8-7r8f-9jp8.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}]}