CVE-2022-22971: Medium severity vmware spring framework vulnerability
A flaw was found in Spring Framework Applications. Applications that use STOMP over the WebSocket endpoint are vulnerable to a denial of service attack caused by an authenticated user.
Other sources
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.
Vmware Tanzu Spring Framework is vulnerable to a denial of service, caused by a flaw with a STOMP over WebSocket endpoint. By sending a specially-crafted request, a remote authenticated attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-22971?
CVE-2022-22971 is a vulnerability in Spring Framework applications that allows an authenticated user to launch a denial of service (DoS) attack.
Which versions of Spring Framework are affected by CVE-2022-22971?
Versions of Spring Framework prior to 5.3.20+, 5.2.22+, and old unsupported versions are affected by CVE-2022-22971.
How can an authenticated user exploit CVE-2022-22971?
An authenticated user can exploit CVE-2022-22971 to launch a denial of service (DoS) attack on an application with a STOMP over WebSocket endpoint.
What is the severity of CVE-2022-22971?
CVE-2022-22971 has a severity value of 6.5, which is considered medium.
Is there a fix available for CVE-2022-22971?
Yes, the fix for CVE-2022-22971 is to upgrade to Spring Framework versions 5.3.20+ or 5.2.22+.