CVE-2022-22970 (Medium) detected in spring-beans-4.3.2.RELEASE.jar, spring-core-4.3.2.RELEASE.jar #171
Labels
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
CVE-2022-22970 - Medium Severity Vulnerability
spring-beans-4.3.2.RELEASE.jar
Spring Beans
Library home page: https://github.com/spring-projects/spring-framework
Path to dependency file: /pom.xml
Path to vulnerable library: /root/.m2/repository/org/springframework/spring-beans/4.3.2.RELEASE/spring-beans-4.3.2.RELEASE.jar
Dependency Hierarchy:
spring-core-4.3.2.RELEASE.jar
Spring Core
Library home page: https://github.com/spring-projects/spring-framework
Path to dependency file: /pom.xml
Path to vulnerable library: /root/.m2/repository/org/springframework/spring-core/4.3.2.RELEASE/spring-core-4.3.2.RELEASE.jar
Dependency Hierarchy:
Found in HEAD commit: 1d4a86820b5ccc9e51b82198be488c68e9299e40
Found in base branch: master
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.
Publish Date: 2022-05-12
URL: CVE-2022-22970
Base Score Metrics:
Type: Upgrade version
Origin: https://tanzu.vmware.com/security/cve-2022-22970
Release Date: 2022-05-12
Fix Resolution (org.springframework:spring-beans): 5.2.22.RELEASE
Direct dependency fix Resolution (org.springframework.security.oauth:spring-security-oauth2): 2.0.11.RELEASE
Fix Resolution (org.springframework:spring-core): 5.2.22.RELEASE
Direct dependency fix Resolution (org.springframework.security.oauth:spring-security-oauth2): 2.0.11.RELEASE
⛑️ Automatic Remediation is available for this issue
The text was updated successfully, but these errors were encountered: