In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial of service (DoS) condition.
Specifically, an application is vulnerable when the following is true:
  *  The application evaluates user-supplied SpEL expressions.
                
            Metrics
Affected Vendors & Products
References
        History
                    Wed, 18 Jun 2025 12:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Netapp
         Netapp active Iq Unified Manager Netapp oncommand Insight Vmware Vmware spring Framework  | 
|
| CPEs | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:* cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:* cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:* cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:* cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:*  | 
|
| Vendors & Products | 
        
        Netapp
         Netapp active Iq Unified Manager Netapp oncommand Insight Vmware Vmware spring Framework  | 
Fri, 22 Nov 2024 12:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
         | 
Wed, 06 Nov 2024 02:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Redhat ocp Tools
         | 
|
| CPEs | cpe:/a:redhat:ocp_tools:4.12::el8 cpe:/a:redhat:ocp_tools:4.13::el8 cpe:/a:redhat:ocp_tools:4.14::el8 cpe:/a:redhat:ocp_tools:4.15::el8  | 
|
| Vendors & Products | 
        
        Redhat ocp Tools
         | 
Wed, 30 Oct 2024 19:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | CWE-770 | 
Tue, 10 Sep 2024 02:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Redhat
         Redhat apache Camel Spring Boot  | 
|
| CPEs | cpe:/a:redhat:apache_camel_spring_boot:4.4.2 | |
| Vendors & Products | 
        
        Redhat
         Redhat apache Camel Spring Boot  | 
Tue, 20 Aug 2024 21:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | CWE-400 | |
| References | 
         | |
| Metrics | 
        
        
        threat_severity
         
  | 
    
        
        
        threat_severity
         
  | 
Tue, 20 Aug 2024 14:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Tue, 20 Aug 2024 07:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial of service (DoS) condition. Specifically, an application is vulnerable when the following is true: * The application evaluates user-supplied SpEL expressions. | |
| Title | CVE-2024-38808: Spring Expression DoS Vulnerability | |
| References | 
         | |
| Metrics | 
        
        cvssV3_1
         
  | 
Status: PUBLISHED
Assigner: vmware
Published: 2024-08-20T07:12:44.736Z
Updated: 2024-10-30T18:41:27.943Z
Reserved: 2024-06-19T22:31:57.187Z
Link: CVE-2024-38808
Updated: 2024-09-20T16:03:07.732Z
Status : Analyzed
Published: 2024-08-20T08:15:05.023
Modified: 2025-06-18T12:10:28.553
Link: CVE-2024-38808
ReportizFlow