spring-beans is vulnerable to Denial of Service (DoS)
59
Medium Risk
spring-beans data binding calls list.get(index) after autoGrowCollectionLimit has stopped further growth. Standard lists throw IndexOutOfBoundsException, but a list that allocates on get can grow without bound. Untrusted property paths can therefore exhaust memory. The patch does not navigate past the current list size.
You are affected if you are using a version that falls within the vulnerable range and Spring data binding applies untrusted property paths to a List that allocates on get(index).
spring-beans is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 7.0.8.
Upgrade the org.springframework:spring-beans library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant