Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-22976

Опубликовано: 17 мая 2022
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

Spring Security versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, and earlier unsupported versions contain an integer overflow vulnerability. When using the BCrypt class with the maximum work factor (31), the encoder does not perform any salt rounds, due to an integer overflow error. The default settings are not affected by this CVE.

A flaw was found in Spring Framework. The encoder does not perform any salt rounds when using the BCrypt class with the maximum work factor (31) due to an integer overflow error.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Clients 2springframeworkNot affected
Red Hat build of QuarkusspringframeworkNot affected
Red Hat Data Grid 8springframeworkNot affected
Red Hat Decision Manager 7springframeworkFix deferred
Red Hat Integration Camel K 1springframeworkNot affected
Red Hat Integration Camel Quarkus 1springframeworkNot affected
Red Hat Integration Data Virtualisation OperatorspringframeworkOut of support scope
Red Hat JBoss BRMS 5springframeworkOut of support scope
Red Hat JBoss Data Grid 7springframeworkOut of support scope
Red Hat JBoss Data Virtualization 6springframeworkOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2087214springframework: BCrypt skips salt rounds for work factor of 31

EPSS

Процентиль: 58%
0.0036
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 3 лет назад

Spring Security versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, and earlier unsupported versions contain an integer overflow vulnerability. When using the BCrypt class with the maximum work factor (31), the encoder does not perform any salt rounds, due to an integer overflow error. The default settings are not affected by this CVE.

CVSS3: 5.3
nvd
больше 3 лет назад

Spring Security versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, and earlier unsupported versions contain an integer overflow vulnerability. When using the BCrypt class with the maximum work factor (31), the encoder does not perform any salt rounds, due to an integer overflow error. The default settings are not affected by this CVE.

CVSS3: 5.3
debian
больше 3 лет назад

Spring Security versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, a ...

CVSS3: 5.3
github
больше 3 лет назад

Integer overflow in BCrypt class in Spring Security

EPSS

Процентиль: 58%
0.0036
Низкий

5.3 Medium

CVSS3