CVE-2024-38809
EUVD-2024-269627.09.2024, 17:15
Applications that parse ETags from "If-Match" or "If-None-Match" request headers are vulnerable to DoS attack. Users of affected versions should upgrade to the corresponding fixed version. Users of older, unsupported versions could enforce a size limit on "If-Match" and "If-None-Match" headers, e.g. through a Filter.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| vmware | spring_framework | 6.1.0 ≤ 𝑥 ≤ 6.1.11 | ADP |
| vmware | spring_framework | 6.0.0 ≤ 𝑥 ≤ 6.0.22 | ADP |
| vmware | spring_framework | 5.3.0 ≤ 𝑥 ≤ 5.3.37 | ADP |
Debian Releases
Ubuntu Releases