CVE-2022-22950

CVSS v3.1 6.5 (Medium)
65% Progress
CVSS v2.0 4 (Medium)
40% Progress
EPSS 0.08 % (36th)
0.08% Progress
Affected Products 1
Advisories 1

n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition.

Weaknesses
CWE-770
Allocation of Resources Without Limits or Throttling
CVE Status
PUBLISHED
CNA
VMware
Published Date
2022-04-01 23:15:13
(2 years ago)
Updated Date
2022-06-22 13:53:48
(2 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Vmware Spring Framework prior 5.2.20 version cpe:2.3:a:vmware:spring_framework < 5.2.20
  Vmware Spring Framework from 5.3.0 version and prior 5.3.17 version cpe:2.3:a:vmware:spring_framework >= 5.3.0 < 5.3.17
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...