spring-boot is vulnerable to Observable Timing Discrepancy
75
High Risk
Affected versions of this package are vulnerable to observable timing discrepancies during DevTools remote secret comparison, which may allow an attacker on the same network to infer the secret through repeated measurements. In extreme cases, successful secret recovery could allow unauthorized class uploads and remote code execution in the target application.
You are affected if using a vulnerable version.
spring-boot is vulnerable to Observable Timing Discrepancy in versions 2.7.0 - 2.7.32, 3.3.0 - 3.3.18, 3.4.0 - 3.4.15, 3.5.0 - 3.5.13 and 4.0.0 - 4.0.5.
Upgrade the org.springframework.boot:spring-boot library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant