CVE-2022-22950: Input Validation
A flaw was found in the Spring Framework. This flaw allows an attacker to craft a special Spring Expression, causing a denial of service.
Other sources
In Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition.
References:
https://tanzu.vmware.com/security/cve-2022-22950
— Red Hat
VMware Tanzu Spring Framework is vulnerable to a denial of service, caused by improper input validation. By sending a specially-crafted crafted SpEL expression, a remote attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-22950?
CVE-2022-22950 is a vulnerability found in the Spring Framework that allows an attacker to craft a special Spring Expression Language (SpEL) expression that may cause a denial of service (DoS) condition.
How does CVE-2022-22950 affect the Spring Framework?
CVE-2022-22950 affects Spring Framework versions 5.3.0 to 5.3.16, as well as older unsupported versions.
What is the severity of CVE-2022-22950?
CVE-2022-22950 has a severity rating of high (7 out of 10).
Which software versions are affected by CVE-2022-22950?
CVE-2022-22950 affects Spring Framework versions 5.3.0 to 5.3.16, and older unsupported versions. The issue can be remedied by updating to version 5.3.17 or later.
How can I mitigate the CVE-2022-22950 vulnerability?
To mitigate the CVE-2022-22950 vulnerability, update your Spring Framework installation to version 5.3.17 or later.