CVE-2022-22978
published 2022-05-19CVE-2022-22978: In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on…
PriorityP261critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
10.04%
95.1th percentile
In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | financial_services_crime_and_compliance_management_studio | — | — |
| oracle | financial_services_crime_and_compliance_management_studio | — | — |
| vmware | spring_security | < 5.5.7 | 5.5.7 |
| vmware | spring_security | — | — |
| vmware | spring_security | >= 5.6.0 < 5.6.4 | 5.6.4 |
Detection & IOCsextracted from sources · hover to see the quote
- →Applications using RegexRequestMatcher with '.' in the regular expression are vulnerable to authorization bypass — audit all RegexRequestMatcher configurations for unescaped '.' patterns ↗
- →The bypass is servlet-container-dependent — test against all servlet containers in use, as misconfiguration of RegexRequestMatcher can be trivially exploited remotely over HTTP/HTTPS ↗
- ·Affected Spring Security versions are prior to 5.4.11, 5.5.7, and 5.6.4; older unsupported versions are also vulnerable ↗
- ·Red Hat OpenShift Container Platform 4 (jenkins package) is confirmed affected; multiple other Red Hat products are not affected or out of support scope ↗
- ·Red Hat Decision Manager 7 and Red Hat Process Automation 7 have fixes deferred — treat as unpatched in those environments ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Base (Spring Security) — CVE-2022-22978
vendor_oracle·2023-04-15·CVSS 9.8
CVE-2022-22978 [CRITICAL] Oracle Oracle Financial Services Applications Risk Matrix: Base (Spring Security) — CVE-2022-22978
Oracle Oracle Financial Services Applications Risk Matrix: Base (Spring Security) vulnerability
CVE: CVE-2022-22978
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Message Bus (Spring Security) — CVE-2022-22978
vendor_oracle·2023-01-15·CVSS 9.8
CVE-2022-22978 [CRITICAL] Oracle Oracle Communications Applications Risk Matrix: Message Bus (Spring Security) — CVE-2022-22978
Oracle Oracle Communications Applications Risk Matrix: Message Bus (Spring Security) vulnerability
CVE: CVE-2022-22978
CVSS: 9.8
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
Oracle
Oracle Oracle Communications Risk Matrix: Signaling (Spring Security) — CVE-2022-22978
vendor_oracle·2022-10-15·CVSS 9.8
CVE-2022-22978 [CRITICAL] Oracle Oracle Communications Risk Matrix: Signaling (Spring Security) — CVE-2022-22978
Oracle Oracle Communications Risk Matrix: Signaling (Spring Security) vulnerability
CVE: CVE-2022-22978
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Studio (Spring Security) — CVE-2022-22978
vendor_oracle·2022-07-15·CVSS 9.8
CVE-2022-22978 [CRITICAL] Oracle Oracle Financial Services Applications Risk Matrix: Studio (Spring Security) — CVE-2022-22978
Oracle Oracle Financial Services Applications Risk Matrix: Studio (Spring Security) vulnerability
CVE: CVE-2022-22978
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
Red Hat
springframework: Authorization Bypass in RegexRequestMatcher
vendor_redhat·2022-05-16·CVSS 9.8
CVE-2022-22978 [CRITICAL] CWE-625 springframework: Authorization Bypass in RegexRequestMatcher
springframework: Authorization Bypass in RegexRequestMatcher
In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.
A flaw was found in Spring Security. When using RegexRequestMatcher, an easy misconfiguration can bypass some servlet containers. Applications using RegexRequestMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.
Package: springframework (A-MQ Clients 2) - Not affected
Package: springframework (Red Hat build of Quarkus) - Not affected
Package: springframework (Red Hat Data Grid
GHSA
Authorization bypass in Spring Security
ghsa·2022-05-20
CVE-2022-22978 [CRITICAL] CWE-285 Authorization bypass in Spring Security
Authorization bypass in Spring Security
In Spring Security versions 5.5.6 and 5.5.7 and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.
OSV
Authorization bypass in Spring Security
osv·2022-05-20
CVE-2022-22978 [CRITICAL] Authorization bypass in Spring Security
Authorization bypass in Spring Security
In Spring Security versions 5.5.6 and 5.5.7 and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.
OSV
CVE-2022-22978: In spring security versions prior to 5
osv·2022-05-19·CVSS 9.8
CVE-2022-22978 [CRITICAL] CVE-2022-22978: In spring security versions prior to 5
In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.
No detection rules found.
No public exploits indexed.
Qualys
Oracle Security Updates: Critical Patch April 2023 Advisory | Qualys
blogs_qualys·2023-04-19
Oracle Security Updates: Critical Patch April 2023 Advisory | Qualys
#### Table of Contents
- Qualys QID Coverage
- Notable Oracle Vulnerabilities Patched
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
- Rapid Response with Patch Management (PM)
Oracle has released the second quarterly edition of Critical Patch Update, which contains a group of patches for 433 security vulnerabilities. Some of the vulnerabilities addressed this month impact various products. These patches address vulnerabilities in Oracle code and third-party components included in Oracle products.
During Q2 2023 Oracle Critical Patch Update, the Oracle Communications product suite recorded the highest number of patches at 77, constituting 17% of the total patches released. The Oracle Financial Services Applications and Oracle Fusion Mi
Qualys
Oracle Patch Tuesday April 2023 Security Update Review
blogs_qualys·2023-04-19
Oracle Patch Tuesday April 2023 Security Update Review
## Table of Contents
Qualys QID Coverage
Notable Oracle Vulnerabilities Patched
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Rapid Response with Patch Management (PM)
Oracle has released the second quarterly edition of Critical Patch Update, which contains a group of patches for 433 security vulnerabilities. Some of the vulnerabilities addressed this month impact various products. These patches address vulnerabilities in Oracle code and third-party components included in Oracle products.
During Q2 2023 Oracle Critical Patch Update, the Oracle Communications product suite recorded the highest number of patches at 77, constituting 17% of the total patches released. The Oracle Financial Services Applications and Oracle Fusion Middlewar
2022-05-19
Published