#VU100680 Input validation error in Pivotal Spring Framework - CVE-2024-38828
Published: November 20, 2024 / Updated: April 16, 2025
Pivotal Spring Framework
Pivotal
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input passed via Spring MVC controller method with @RequestBody byte[] parameter. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.