Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-22976

Опубликовано: 19 мая 2022
Источник: nvd
CVSS3: 5.3
CVSS2: 4.3
EPSS Низкий

Описание

Spring Security versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, and earlier unsupported versions contain an integer overflow vulnerability. When using the BCrypt class with the maximum work factor (31), the encoder does not perform any salt rounds, due to an integer overflow error. The default settings are not affected by this CVE.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:*
Версия от 5.2.1 (включая) до 5.5.7 (исключая)
cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:*
Версия от 5.6.0 (включая) до 5.6.4 (исключая)
cpe:2.3:a:vmware:spring_security:5.2.0:-:*:*:*:*:*:*
Конфигурация 2

Одно из

cpe:2.3:a:oracle:financial_services_crime_and_compliance_management_studio:8.0.8.2.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:financial_services_crime_and_compliance_management_studio:8.0.8.3.0:*:*:*:*:*:*:*
Конфигурация 3

Одно из

cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*

EPSS

Процентиль: 58%
0.0036
Низкий

5.3 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-190
CWE-190

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 3 лет назад

Spring Security versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, and earlier unsupported versions contain an integer overflow vulnerability. When using the BCrypt class with the maximum work factor (31), the encoder does not perform any salt rounds, due to an integer overflow error. The default settings are not affected by this CVE.

CVSS3: 5.3
redhat
больше 3 лет назад

Spring Security versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, and earlier unsupported versions contain an integer overflow vulnerability. When using the BCrypt class with the maximum work factor (31), the encoder does not perform any salt rounds, due to an integer overflow error. The default settings are not affected by this CVE.

CVSS3: 5.3
debian
больше 3 лет назад

Spring Security versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, a ...

CVSS3: 5.3
github
больше 3 лет назад

Integer overflow in BCrypt class in Spring Security

EPSS

Процентиль: 58%
0.0036
Низкий

5.3 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-190
CWE-190