CVE-2022-22970: High severity vmware spring framework vulnerability
A flaw was found in Spring Framework. Applications that handle file uploads are vulnerable to a denial of service (DoS) attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.
Other sources
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.
Vmware Tanzu Spring Framework is vulnerable to a denial of service, caused by a flaw in the handling of file uploads. By sending a specially-crafted request, a remote authenticated attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-22970?
CVE-2022-22970 is a vulnerability found in Spring Framework where applications that handle file uploads are vulnerable to a DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.
Which versions of Spring Framework are affected by CVE-2022-22970?
Spring Framework versions prior to 5.3.20+, 5.2.22+, and old unsupported versions are affected by CVE-2022-22970.
What is the severity of CVE-2022-22970?
CVE-2022-22970 has a severity value of 5.3, which is considered medium.
How can I fix CVE-2022-22970?
To fix CVE-2022-22970, upgrade to Spring Framework version 5.3.20+ or 5.2.22+ if you are using an affected version.
Where can I find more information about CVE-2022-22970?
You can find more information about CVE-2022-22970 on the following references: [Link 1](https://tanzu.vmware.com/security/cve-2022-22970), [Link 2](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=2087273), [Link 3](https://access.redhat.com/errata/RHSA-2022:5532).