First published: Wed May 11 2022(Updated: )
A flaw was found in Spring Framework. Applications that handle file uploads are vulnerable to a denial of service (DoS) attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.
Credit: security@vmware.com security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/springframework | <5.3.20 | 5.3.20 |
redhat/springframework | <5.2.22 | 5.2.22 |
maven/org.springframework:spring-beans | >=5.3.0<5.3.20 | 5.3.20 |
maven/org.springframework:spring-beans | <=5.2.21.RELEASE | 5.2.22.RELEASE |
VMware Spring Framework | <=5.2.21 | |
VMware Spring Framework | >=5.3.0<=5.3.19 | |
Oracle Financial Services Crime And Compliance Management Studio | =8.0.8.2.0 | |
Oracle Financial Services Crime And Compliance Management Studio | =8.0.8.3.0 | |
Netapp Active Iq Unified Manager Linux | ||
Netapp Active Iq Unified Manager Vmware Vsphere | ||
Netapp Active Iq Unified Manager Windows | ||
Netapp Brocade San Navigator | ||
Netapp Cloud Secure Agent | ||
NetApp OnCommand Insight |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2022-22970 is a vulnerability found in Spring Framework where applications that handle file uploads are vulnerable to a DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.
Spring Framework versions prior to 5.3.20+, 5.2.22+, and old unsupported versions are affected by CVE-2022-22970.
CVE-2022-22970 has a severity value of 5.3, which is considered medium.
To fix CVE-2022-22970, upgrade to Spring Framework version 5.3.20+ or 5.2.22+ if you are using an affected version.
You can find more information about CVE-2022-22970 on the following references: [Link 1](https://tanzu.vmware.com/security/cve-2022-22970), [Link 2](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=2087273), [Link 3](https://access.redhat.com/errata/RHSA-2022:5532).