High severity7.5NVD Advisory· Published May 26, 2023· Updated Jun 17, 2026
CVE-2023-20883
CVE-2023-20883
Description
In Spring Boot versions 3.0.0 - 3.0.6, 2.7.0 - 2.7.11, 2.6.0 - 2.6.14, 2.5.0 - 2.5.14 and older unsupported versions, there is potential for a denial-of-service (DoS) attack if Spring MVC is used together with a reverse proxy cache.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.springframework.boot:spring-boot-autoconfigureMaven | >= 3.0.0, < 3.0.7 | 3.0.7 |
org.springframework.boot:spring-boot-autoconfigureMaven | >= 2.7.0, < 2.7.12 | 2.7.12 |
org.springframework.boot:spring-boot-autoconfigureMaven | >= 2.6.0, < 2.6.15 | 2.6.15 |
org.springframework.boot:spring-boot-autoconfigureMaven | < 2.5.15 | 2.5.15 |
Affected products
2Patches
Vulnerability mechanics
References
10- github.com/advisories/GHSA-xf96-w227-r7c4ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-20883ghsaADVISORY
- spring.io/security/cve-2023-20883nvdVendor AdvisoryWEB
- github.com/spring-projects/spring-boot/commit/418dd1ba5bdad79b55a043000164bfcbda2acd78ghsaWEB
- github.com/spring-projects/spring-boot/issues/35552ghsaWEB
- github.com/spring-projects/spring-boot/releases/tag/v2.5.15ghsaWEB
- github.com/spring-projects/spring-boot/releases/tag/v2.6.15ghsaWEB
- github.com/spring-projects/spring-boot/releases/tag/v2.7.12ghsaWEB
- security.netapp.com/advisory/ntap-20230703-0008ghsaWEB
- security.netapp.com/advisory/ntap-20230703-0008/nvd
News mentions
0No linked articles in our index yet.