漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Unbounded persistent session allocation via repeated initialize requests
Vulnerability Description
The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on the number of sessions it retains, and by default does not require clients to be authenticated. As a result, a remote attacker can cause the server to accumulate an unbounded number of sessions over time, gradually exhausting available memory and ultimately causing a Denial of Service that affects all legitimate clients.
Affected versions:
Spring AI: 2.0.0
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
不加限制或调节的资源分配
Vulnerability Title
Spring AI 资源管理错误漏洞
Vulnerability Description
Spring AI是美国Spring公司的一款人工智能框架。 Spring AI 2.0.0版本存在资源管理错误漏洞,该漏洞源于MCP Streamable HTTP服务器传输(WebFlux和WebMvc变体)未限制保留的会话数量且默认不要求客户端身份验证,远程攻击者可利用此漏洞导致服务器累积无限会话,逐渐耗尽内存,最终造成拒绝服务,影响所有合法客户端。
CVSS Information
N/A
Vulnerability Type
N/A