CVE-2022-22978
CRITICALVmware Spring Security < 5.5.7 - Incorrect Authorization
Title source: ruleDescription
In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.
Exploits (9)
nomisec
WORKING POC
12 stars
by ducluongtran9121 · poc
https://github.com/ducluongtran9121/CVE-2022-22978-PoC
nomisec
by BoB13-Opensource-Contribution-Team9 · poc
https://github.com/BoB13-Opensource-Contribution-Team9/CVE-2022-22978
References (1)
Scores
CVSS v3
9.8
EPSS
0.9071
EPSS Percentile
99.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-863
Status
published
Products (6)
netapp/active_iq_unified_manager
(3 CPE variants)
oracle/financial_services_crime_and_compliance_management_studio
8.0.8.2.0
oracle/financial_services_crime_and_compliance_management_studio
8.0.8.3.0
org.springframework.security/spring-security-core
5.5.0 - 5.5.7Maven
org.springframework.security/spring-security-web
5.5.0 - 5.5.7Maven
vmware/spring_security
< 5.5.7
Published
May 19, 2022
Tracked Since
Feb 18, 2026