spring-batch-infrastructure is vulnerable to Denial of Service (DoS)
59
Medium Risk
spring-batch-infrastructure FlatFileItemReader can assemble a single logical record from many physical lines. A crafted file can force excessive CPU and memory while joining quoted or JSON multi-line records. SimpleRecordSeparatorPolicy, the default, is not affected. The patch bounds multi-line record assembly.
You are affected if you are using a version that falls within the vulnerable range and FlatFileItemReader uses DefaultRecordSeparatorPolicy or JsonRecordSeparatorPolicy.
spring-batch-infrastructure is vulnerable to Denial of Service (DoS) in versions 4.3.0 - 6.0.4.
Upgrade the org.springframework.batch:spring-batch-infrastructure library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant