CVE-2023-20883: VMware Spring Boot
High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.
In Spring Boot versions 3.0.0 - 3.0.6, 2.7.0 - 2.7.11, 2.6.0 - 2.6.14, 2.5.0 - 2.5.14 and older unsupported versions, there is potential for a denial-of-service (DoS) attack if Spring MVC is used together with a reverse proxy cache.
Affected products
- VMware Spring Boot: before 2.5.14 (fixed in 2.5.14); from 2.6.0, up to and including 2.6.14; from 2.7.0, up to and including 2.7.11; from 3.0.0, up to and including 3.0.6
Published 2023-05-26. Last modified 2026-06-17.