Medium severity6.5NVD Advisory· Published Apr 13, 2023· Updated Jun 17, 2026
CVE-2023-20863
CVE-2023-20863
Description
In spring framework versions prior to 5.2.24 release+ ,5.3.27+ and 6.0.8+ , it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.springframework:spring-expressionMaven | >= 6.0.0, < 6.0.8 | 6.0.8 |
org.springframework:spring-expressionMaven | >= 5.3.0, < 5.3.27 | 5.3.27 |
org.springframework:spring-expressionMaven | < 5.2.24.RELEASE | 5.2.24.RELEASE |
Affected products
2- spring framework/spring frameworkdescription
Patches
Vulnerability mechanics
References
8- github.com/advisories/GHSA-wxqc-pxw9-g2p8ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-20863ghsaADVISORY
- spring.io/security/cve-2023-20863nvdVendor AdvisoryWEB
- github.com/spring-projects/spring-framework/commit/965a6392757d20f9db19241126fcc719a51eac15ghsaWEB
- github.com/spring-projects/spring-framework/commit/b73f5fcac22555f844cf27a7eeb876cb9d7f7f7eghsaWEB
- github.com/spring-projects/spring-framework/commit/ebc82654282bda547fbc20a9749ab1bda886a46fghsaWEB
- security.netapp.com/advisory/ntap-20240524-0015ghsaWEB
- security.netapp.com/advisory/ntap-20240524-0015/nvd
News mentions
0No linked articles in our index yet.