CVE-2024-22271
Spring Cloud vulnerability analysis and mitigation

Overview

In Spring Cloud Function framework, versions 4.1.x prior to 4.1.2 and 4.0.x prior to 4.0.8, a vulnerability has been identified that makes applications susceptible to Denial of Service (DOS) attacks when attempting to compose functions with non-existing functions. This vulnerability specifically affects users of the Spring Cloud Function Web module (Spring Security).

Technical details

The vulnerability is classified as a medium severity issue and has been assigned CVE-2024-22271. The vulnerability stems from improper input validation (CWE-20) when attempting to compose functions with non-existing functions in the Spring Cloud Function Web module. The issue affects Spring Cloud Function Framework versions 4.1.0 to 4.1.2 and 4.0.0 to 4.0.8 (NVD).

Impact

When exploited, this vulnerability can result in a Denial of Service (DOS) condition for applications using the Spring Cloud Function Web module. The impact is specifically limited to scenarios where applications attempt to compose functions with non-existing functions (ASEC).

Exploitability

The vulnerability requires the application to be using the Spring Cloud Function Web module and attempting to compose functions with non-existing functions. No authentication is required to exploit this vulnerability, making it potentially accessible to remote attackers (Spring Security).

Mitigation and workarounds

Users of affected versions are advised to upgrade to the fixed versions: 4.1.x users should upgrade to version 4.1.2, and 4.0.x users should upgrade to version 4.0.8. No additional mitigation steps are necessary beyond the version upgrade (Spring Security).

Community reactions

The vulnerability was identified and responsibly reported by security researcher devme4f from VNPT-VCI. The Spring security team has acknowledged the issue and provided fixes in their latest releases (Spring Security).

Additional resources


SourceThis report was generated using AI

Related Spring Cloud vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2022-22963CRITICAL9.8
  • MySQL Enterprise Monitor logoMySQL Enterprise Monitor
  • cpe:2.3:a:oracle:retail_xstore_point_of_service
YesYesApr 01, 2022
CVE-2024-22271HIGH8.2
  • Spring Cloud logoSpring Cloud
  • org.springframework.cloud:spring-cloud-function-context
NoYesJul 09, 2024
CVE-2026-40990MEDIUM6.5
  • Spring Cloud logoSpring Cloud
  • org.springframework.cloud:spring-cloud-function-context
NoYesJun 01, 2026
CVE-2026-40989MEDIUM6.5
  • Spring Cloud logoSpring Cloud
  • org.springframework.cloud:spring-cloud-function-context
NoYesJun 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management