Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-22950

Опубликовано: 28 мар. 2022
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition.

A flaw was found in the Spring Framework. This flaw allows an attacker to craft a special Spring Expression, causing a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Clients 2spring-expressionNot affected
Logging Subsystem for Red Hat OpenShiftspring-expressionWill not fix
Red Hat AMQ Broker 7spring-expressionNot affected
Red Hat build of Quarkusspring-expressionNot affected
Red Hat Data Grid 8spring-expressionWill not fix
Red Hat Integration Camel K 1spring-expressionWill not fix
Red Hat Integration Camel Quarkus 1spring-expressionWill not fix
Red Hat Integration Data Virtualisation Operatorspring-expressionOut of support scope
Red Hat JBoss Data Grid 7spring-expressionOut of support scope
Red Hat JBoss Data Virtualization 6spring-expressionOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2069414spring-expression: Denial of service via specially crafted SpEL expression

EPSS

Процентиль: 89%
0.04547
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 3 лет назад

n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition.

CVSS3: 6.5
nvd
около 3 лет назад

n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition.

CVSS3: 6.5
debian
около 3 лет назад

n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versi ...

CVSS3: 6.5
github
около 3 лет назад

Allocation of Resources Without Limits or Throttling in Spring Framework

EPSS

Процентиль: 89%
0.04547
Низкий

7.5 High

CVSS3