CVE-2022-22976
MEDIUMVmware Spring Security < 5.5.7 - Integer Overflow
Title source: ruleDescription
Spring Security versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, and earlier unsupported versions contain an integer overflow vulnerability. When using the BCrypt class with the maximum work factor (31), the encoder does not perform any salt rounds, due to an integer overflow error. The default settings are not affected by this CVE.
Exploits (1)
nomisec
SCANNER
1 stars
by spring-io · poc
https://github.com/spring-io/cve-2022-22976-bcrypt-skips-salt
Scores
CVSS v3
5.3
EPSS
0.0036
EPSS Percentile
58.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Details
CWE
CWE-190
Status
published
Products (6)
netapp/active_iq_unified_manager
(3 CPE variants)
oracle/financial_services_crime_and_compliance_management_studio
8.0.8.2.0
oracle/financial_services_crime_and_compliance_management_studio
8.0.8.3.0
org.springframework.security/spring-security-core
5.2.0.RELEASE - 5.5.7Maven
vmware/spring_security
5.2.0
vmware/spring_security
5.2.1 - 5.5.7
Published
May 19, 2022
Tracked Since
Feb 18, 2026