CVE-2024-38808

In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial of service (DoS) condition. Specifically, an application is vulnerable when the following is true: * The application evaluates user-supplied SpEL expressions.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*
cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*

History

18 Jun 2025, 12:10

Type Values Removed Values Added
CPE cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*
cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*
First Time Netapp
Netapp oncommand Insight
Netapp active Iq Unified Manager
Vmware
Vmware spring Framework
References () https://spring.io/security/cve-2024-38808 - () https://spring.io/security/cve-2024-38808 - Vendor Advisory
References () https://security.netapp.com/advisory/ntap-20240920-0002/ - () https://security.netapp.com/advisory/ntap-20240920-0002/ - Third Party Advisory

21 Nov 2024, 09:26

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20240920-0002/ -

30 Oct 2024, 19:35

Type Values Removed Values Added
CWE CWE-770

20 Aug 2024, 15:44

Type Values Removed Values Added
Summary
  • (es) En las versiones de Spring Framework 5.3.0 - 5.3.38 y versiones anteriores no compatibles, es posible que un usuario proporcione una expresión Spring Expression Language (SpEL) especialmente manipulada que puede causar una condición de denegación de servicio (DoS). Específicamente, una aplicación es vulnerable cuando se cumple lo siguiente: * La aplicación evalúa expresiones SpEL proporcionadas por el usuario.

20 Aug 2024, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-20 08:15

Updated : 2025-06-18 12:10


NVD link : CVE-2024-38808

Mitre link : CVE-2024-38808

CVE.ORG link : CVE-2024-38808


JSON object : View

Products Affected

netapp

  • active_iq_unified_manager
  • oncommand_insight

vmware

  • spring_framework
CWE
CWE-770

Allocation of Resources Without Limits or Throttling