Red Hat Bugzilla – Bug 1643043
CVE-2018-15756 springframework: DoS Attack via Range Requests
Last modified: 2018-10-25 08:23:34 EDT
Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and older unsupported versions on the 4.2.x branch provide support for range requests when serving static resources through the ResourceHttpRequestHandler, or starting in 5.0 when an annotated controller returns an org.springframework.core.io.Resource. A malicious user (or attacker) can add a range header with a high number of ranges, or with wide ranges that overlap, or both, for a denial of service attack.
External References: https://pivotal.io/security/cve-2018-15756
Created springframework tracking bugs for this issue: Affects: fedora-all [bug 1643044]