CVE-2024-38809: Spring Framework DoS via conditional HTTP request
CVE-2024-38809: Spring Framework DoS via conditional HTTP request
Applications that parse ETags from "If-Match" or "If-None-Match" request headers are vulnerable to DoS attack.
This issue was responsibly reported by Seokchan Yoon.
해당 동작을 하는 스프링 부트 애플리케이션이라면 아래의 버전으로 업그레이드 권장
Spring Boot 2.7 → 2.7.21.1
Spring Boot 3.0 → 3.0.16.1
Spring Boot 3.1 → 3.1.12.1
