CVE-2022-22970
published 2022-05-12CVE-2022-22970: In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if…
PriorityP429medium5.3CVSS 3.1
AVNACHPRLUINSUCNINAH
EPSS
1.98%
78.3th percentile
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libspring-java | — | — |
| oracle | financial_services_crime_and_compliance_management_studio | — | — |
| oracle | financial_services_crime_and_compliance_management_studio | — | — |
| vmware | spring_framework | <= 5.2.21 | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | 5.3.0 – 5.3.19 | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:N/A:P
osv5.3MEDIUM
vendor_debian5.3LOW
vendor_oracle5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Communications Risk Matrix: Signaling (Spring Framework) — CVE-2022-22970
vendor_oracle·2023-01-15·CVSS 5.3
CVE-2022-22970 [MEDIUM] Oracle Oracle Communications Risk Matrix: Signaling (Spring Framework) — CVE-2022-22970
Oracle Oracle Communications Risk Matrix: Signaling (Spring Framework) vulnerability
CVE: CVE-2022-22970
CVSS: 5.3
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
Red Hat
springframework: DoS via data binding to multipartFile or servlet part
vendor_redhat·2022-05-11·CVSS 5.3
CVE-2022-22970 [MEDIUM] CWE-770 springframework: DoS via data binding to multipartFile or servlet part
springframework: DoS via data binding to multipartFile or servlet part
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.
A flaw was found in Spring Framework. Applications that handle file uploads are vulnerable to a denial of service (DoS) attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.
Package: springframework (A-MQ Clients 2) - Not affected
Package: springframework (Red Hat build of Quarkus) - Not affected
Package: springframework (Red Hat Data Grid 8) - Not affected
Package: springframework (Red Hat Decision Manage
Debian
CVE-2022-22970: libspring-java - In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported vers...
vendor_debian·2022·CVSS 5.3
CVE-2022-22970 [MEDIUM] CVE-2022-22970: libspring-java - In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported vers...
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
OSV
Denial of service in Spring Framework
osv·2022-05-13
CVE-2022-22970 [HIGH] Denial of service in Spring Framework
Denial of service in Spring Framework
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.
GHSA
Denial of service in Spring Framework
ghsa·2022-05-13
CVE-2022-22970 [HIGH] CWE-770 Denial of service in Spring Framework
Denial of service in Spring Framework
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.
OSV
CVE-2022-22970: In spring framework versions prior to 5
osv·2022-05-12·CVSS 5.3
CVE-2022-22970 [MEDIUM] CVE-2022-22970: In spring framework versions prior to 5
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://security.netapp.com/advisory/ntap-20220616-0006/https://tanzu.vmware.com/security/cve-2022-22970https://www.oracle.com/security-alerts/cpujul2022.htmlhttps://security.netapp.com/advisory/ntap-20220616-0006/https://tanzu.vmware.com/security/cve-2022-22970https://www.oracle.com/security-alerts/cpujul2022.html
2022-05-12
Published