Record summary

CVE-2022-22971 has a selected CVSS score of 6.5 (medium); EIP currently links 1 repository PoC and 1 lab environment.

Description

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1
Lab environments
1

Affected products and versions

2
ProductSourceVersion rangeStatus

Spring Framework

CVE ListSpring Framework versions 5.3.x prior to 5.3.20, 5.2.x prior to 5.2.22 and all old and unsupported versionsaffected

org.springframework:spring-messaging

Browse Maven / org.springframework:spring-messaging
GitHub Advisory5.3.0 to < 5.3.20 · Fixed in 5.3.20affected
Before 5.2.22.RELEASE · Fixed in 5.2.22.RELEASEaffected

Proofs of concept

1

Repository PoCs

GitHubtchize/CVE-2022-22971Repository PoCby tchizeStars: 1Not analyzed13 files

81.2 KiB

GitHub

PoC details

Docker lab environments

1
GitHub

rabbit

tchize/CVE-2022-22971Created
Analysis pendingCVE-2022-22971Dockerfile

1 Dockerfile

Structural lab evidence is available; analysis is pending.

References

7