.. _vulnerabilityManagement_securityAdvisory_2024_CVE-2024-38809: CVE-2024-38809 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Data: 2024-08-28 Severity: High CVSS Score: 8.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N) Riferimenti: - `https://ossindex.sonatype.org/vulnerability/CVE-2024-38809 `_ - `https://spring.io/security/cve-2024-38809 `_ Libreria: org.springframework:spring-web <= 5.3.38 **Descrizione** CWE-1333 Spring Framework - Regular expression Denial of Service (ReDoS) Spring Framework DoS via conditional HTTP request Applications that parse ETags from "If-Match" or "If-None-Match" request headers are vulnerable to DoS attack. **GovWay** Versione affette: <= 3.3.15 Risoluzione: 3.3.15.p1