Based on the spring website, In Spring Framework versions 5.3.0 - 5.3.16, 5.2.0 - 5.2.19, and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition
.
What if your application does not implement SpEl expressions? Are you still affected by this vulnerability just because you are using Spring Framework 4.1.5?