github.com
https://github.com/spring-projects/spring-framework CVE-2022-22971
MEDIUM
Allocation of Resources Without Limits or Throttling in Spring Framework
Record summary
CVE-2022-22971 has a selected CVSS score of 6.5 (medium); EIP currently links 1 repository PoC and 1 lab environment.
Description
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.
Description source: CVE List
Exploitation context
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Spring Framework | CVE List | Spring Framework versions 5.3.x prior to 5.3.20, 5.2.x prior to 5.2.22 and all old and unsupported versions | affected |
org.springframework:spring-messagingBrowse Maven / org.springframework:spring-messaging | GitHub Advisory | 5.3.0 to < 5.3.20 · Fixed in 5.3.20 | affected |
| Before 5.2.22.RELEASE · Fixed in 5.2.22.RELEASE | affected |
Proofs of concept
1Repository PoCs
GitHubtchize/CVE-2022-22971Repository PoCby tchizeStars: 1Not analyzed13 files
Docker lab environments
1GitHubrabbit
tchize/CVE-2022-22971Created Analysis pendingCVE-2022-22971Dockerfile
References
7github.com
https://github.com/spring-projects/spring-framework/commit/159a99bbafdd6c01871228113d7042c3f83f360f github.com
https://github.com/spring-projects/spring-framework/commit/dc2947c52df18d5e99cad03383f7d6ba13d031fd nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-22971 security.netapp.comConfirmation
https://security.netapp.com/advisory/ntap-20220616-0003 tanzu.vmware.com
https://tanzu.vmware.com/security/cve-2022-22971 oracle.com
https://www.oracle.com/security-alerts/cpujul2022.html