CVE-2022-22970: High severity VMware Spring Framework vulnerability
A flaw was found in Spring Framework. Applications that handle file uploads are vulnerable to a denial of service (DoS) attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.
Other sources
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/springframeworkto a version that resolves this vulnerability.Fixed in 5.3.20 - Upgrade
Upgrade
redhat/springframeworkto a version that resolves this vulnerability.Fixed in 5.2.22 - Upgrade
Upgrade
maven/org.springframework:spring-beansto a version that resolves this vulnerability.Fixed in 5.3.20 - Upgrade
Upgrade
maven/org.springframework:spring-beansto a version that resolves this vulnerability.Fixed in 5.2.22.RELEASE - Upgrade
Upgrade
Spring Frameworkto a version that resolves this vulnerability.Fixed in 5.3.20+ - Upgrade
Upgrade
Spring Frameworkto a version that resolves this vulnerability.Fixed in 5.2.22+
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-22970?
CVE-2022-22970 is a vulnerability found in Spring Framework where applications that handle file uploads are vulnerable to a DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.
Which versions of Spring Framework are affected by CVE-2022-22970?
Spring Framework versions prior to 5.3.20+, 5.2.22+, and old unsupported versions are affected by CVE-2022-22970.
What is the severity of CVE-2022-22970?
CVE-2022-22970 has a severity value of 5.3, which is considered medium.
How can I fix CVE-2022-22970?
To fix CVE-2022-22970, upgrade to Spring Framework version 5.3.20+ or 5.2.22+ if you are using an affected version.
Where can I find more information about CVE-2022-22970?
You can find more information about CVE-2022-22970 on the following references: [Link 1](https://tanzu.vmware.com/security/cve-2022-22970), [Link 2](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=2087273), [Link 3](https://access.redhat.com/errata/RHSA-2022:5532).