Rewterz Threat Alert – LockBit Ransomware – Active IOCs
April 17, 2023Rewterz Threat Advisory – CVE-2023-28929 – Trend Micro Security Vulnerability
April 17, 2023Rewterz Threat Alert – LockBit Ransomware – Active IOCs
April 17, 2023Rewterz Threat Advisory – CVE-2023-28929 – Trend Micro Security Vulnerability
April 17, 2023Severity
High
Analysis Summary
CVE-2023-20863
VMware Tanzu Spring Framework is vulnerable to a denial of service, caused by improper input validation. By sending a specially crafted SpEL expression, a remote attacker could exploit this vulnerability to cause a denial of service condition.
Impact
- Denial of Service
Indicators Of Compromise
CVE
- CVE-2023-20863
Affected Vendors
VMware
Affected Products
- VMware Tanzu Spring Framework 5.3.0
- VMware Tanzu Spring Framework 6.0.0
- VMware Tanzu Spring Framework 5.2.23.RELEASE
- VMware Tanzu Spring Framework 5.3.26
- VMware Tanzu Spring Framework 6.0.7
- VMware Tanzu Spring Framework 5.2.0.RELEASE
Remediation
Refer to Spring Security Advisories for patch, upgrade or suggested workaround information.