First published: Mon Mar 28 2022(Updated: )
A flaw was found in the Spring Framework. This flaw allows an attacker to craft a special Spring Expression, causing a denial of service.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/ovirt-dependencies | <0:4.5.2-1.el8e | 0:4.5.2-1.el8e |
VMware Spring Framework | <5.2.20 | |
VMware Spring Framework | >=5.3.0<5.3.17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2022-22950 is a vulnerability found in the Spring Framework that allows an attacker to craft a special Spring Expression Language (SpEL) expression that may cause a denial of service (DoS) condition.
CVE-2022-22950 affects Spring Framework versions 5.3.0 to 5.3.16, as well as older unsupported versions.
CVE-2022-22950 has a severity rating of high (7 out of 10).
CVE-2022-22950 affects Spring Framework versions 5.3.0 to 5.3.16, and older unsupported versions. The issue can be remedied by updating to version 5.3.17 or later.
To mitigate the CVE-2022-22950 vulnerability, update your Spring Framework installation to version 5.3.17 or later.