CVE-2022-22979
published 2022-06-21CVE-2022-22979: In Spring Cloud Function versions prior to 3.2.6, it is possible for a user who directly interacts with framework provided lookup functionality to cause a…
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.27%
66.4th percentile
In Spring Cloud Function versions prior to 3.2.6, it is possible for a user who directly interacts with framework provided lookup functionality to cause a denial-of-service condition due to the caching issue in the Function Catalog component of the framework.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| spring_by_vmware_tanzu | spring_cloud_function_framework | — | — |
| vmware | spring_cloud_function | < 3.2.6 | 3.2.6 |
| vmware | spring_cloud_function | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat8.2HIGH
vendor_oracle7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
spring-cloud-function-context: Spring Cloud Function Web DOS Vulnerability
vendor_redhat·2024-07-09·CVSS 8.2
CVE-2024-22271 [HIGH] CWE-400 spring-cloud-function-context: Spring Cloud Function Web DOS Vulnerability
spring-cloud-function-context: Spring Cloud Function Web DOS Vulnerability
In Spring Cloud Function framework, versions 4.1.x prior to 4.1.2, 4.0.x prior to 4.0.8 an application is vulnerable to a DOS attack when attempting to compose functions with non-existing functions.
Specifically, an application is vulnerable when all of the following are true:
User is using Spring Cloud Function Web module
Affected Spring Products and Versions Spring Cloud Function Framework 4.1.0 to 4.1.2 4.0.0 to 4.0.8
References https://spring.io/security/cve-2022-22979 https://checkmarx.com/blog/spring-function-cloud-dos-cve-2022-22979-and-unintended-function-invocation/ History 2020-01-16: Initial vulnerability report published.
A flaw was found in the Spring Cloud Function framework. Affected versions of thi
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Reports (Spring Cloud Function) — CVE-2022-22979
vendor_oracle·2024-01-15·CVSS 7.5
CVE-2022-22979 [HIGH] Oracle Oracle Financial Services Applications Risk Matrix: Reports (Spring Cloud Function) — CVE-2022-22979
Oracle Oracle Financial Services Applications Risk Matrix: Reports (Spring Cloud Function) vulnerability
CVE: CVE-2022-22979
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2024 (JAN 2024)
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Base (Spring Cloud Function) — CVE-2022-22979
vendor_oracle·2023-04-15·CVSS 7.5
CVE-2022-22979 [HIGH] Oracle Oracle Financial Services Applications Risk Matrix: Base (Spring Cloud Function) — CVE-2022-22979
Oracle Oracle Financial Services Applications Risk Matrix: Base (Spring Cloud Function) vulnerability
CVE: CVE-2022-22979
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
GHSA
Spring Cloud Function Framework vulnerable to Denial of Service
ghsa·2024-07-09
CVE-2024-22271 [HIGH] CWE-20 Spring Cloud Function Framework vulnerable to Denial of Service
Spring Cloud Function Framework vulnerable to Denial of Service
In Spring Cloud Function framework, versions 4.1.x prior to 4.1.2, 4.0.x prior to 4.0.8 an application is vulnerable to a DOS attack when attempting to compose functions with non-existing functions.
Specifically, an application is vulnerable when all of the following are true:
User is using Spring Cloud Function Web module
Affected Spring Products and Versions Spring Cloud Function Framework 4.1.0 to 4.1.2 4.0.0 to 4.0.8
References https://spring.io/security/cve-2022-22979 https://checkmarx.com/blog/spring-function-cloud-dos-cve-2022-22979-and-unintended-function-invocation/ History 2020-01-16: Initial vulnerability report published.
OSV
Spring Cloud Function Framework vulnerable to Denial of Service
osv·2024-07-09
CVE-2024-22271 [HIGH] Spring Cloud Function Framework vulnerable to Denial of Service
Spring Cloud Function Framework vulnerable to Denial of Service
In Spring Cloud Function framework, versions 4.1.x prior to 4.1.2, 4.0.x prior to 4.0.8 an application is vulnerable to a DOS attack when attempting to compose functions with non-existing functions.
Specifically, an application is vulnerable when all of the following are true:
User is using Spring Cloud Function Web module
Affected Spring Products and Versions Spring Cloud Function Framework 4.1.0 to 4.1.2 4.0.0 to 4.0.8
References https://spring.io/security/cve-2022-22979 https://checkmarx.com/blog/spring-function-cloud-dos-cve-2022-22979-and-unintended-function-invocation/ History 2020-01-16: Initial vulnerability report published.
GHSA
Denial of Service in Spring Cloud Function
ghsa·2022-06-22
CVE-2022-22979 [HIGH] CWE-770 Denial of Service in Spring Cloud Function
Denial of Service in Spring Cloud Function
In Spring Cloud Function versions prior to 3.2.6, it is possible for a user who directly interacts with framework provided lookup functionality to cause a denial-of-service condition due to the caching issue in the Function Catalog component of the framework.
OSV
Denial of Service in Spring Cloud Function
osv·2022-06-22
CVE-2022-22979 [HIGH] Denial of Service in Spring Cloud Function
Denial of Service in Spring Cloud Function
In Spring Cloud Function versions prior to 3.2.6, it is possible for a user who directly interacts with framework provided lookup functionality to cause a denial-of-service condition due to the caching issue in the Function Catalog component of the framework.
No detection rules found.
No public exploits indexed.
2022-06-21
Published