Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-22970

Опубликовано: 11 мая 2022
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.

A flaw was found in Spring Framework. Applications that handle file uploads are vulnerable to a denial of service (DoS) attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Clients 2springframeworkNot affected
Red Hat build of QuarkusspringframeworkNot affected
Red Hat Data Grid 8springframeworkNot affected
Red Hat Decision Manager 7springframeworkFix deferred
Red Hat Integration Camel K 1springframeworkNot affected
Red Hat Integration Camel Quarkus 1springframeworkNot affected
Red Hat Integration Data Virtualisation OperatorspringframeworkOut of support scope
Red Hat JBoss BRMS 5springframeworkOut of support scope
Red Hat JBoss Data Grid 7springframeworkOut of support scope
Red Hat JBoss Data Virtualization 6springframeworkOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2087272springframework: DoS via data binding to multipartFile or servlet part

EPSS

Процентиль: 52%
0.00288
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 3 лет назад

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.

CVSS3: 5.3
nvd
около 3 лет назад

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.

CVSS3: 5.3
debian
около 3 лет назад

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupp ...

CVSS3: 7.5
github
около 3 лет назад

Denial of service in Spring Framework

EPSS

Процентиль: 52%
0.00288
Низкий

5.3 Medium

CVSS3