CVE-2022-22978

CRITICAL

Vmware Spring Security < 5.5.7 - Incorrect Authorization

Title source: rule

Description

In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.

Exploits (9)

nomisec WORKING POC 16 stars
by DeEpinGh0st · poc
https://github.com/DeEpinGh0st/CVE-2022-22978
nomisec WORKING POC 12 stars
by ducluongtran9121 · poc
https://github.com/ducluongtran9121/CVE-2022-22978-PoC
nomisec WORKING POC 5 stars
by aeifkz · poc
https://github.com/aeifkz/CVE-2022-22978
nomisec WORKING POC 2 stars
by umakant76705 · poc
https://github.com/umakant76705/CVE-2022-22978
gitlab WORKING POC
by cy4n · poc
https://gitlab.com/cy4n/CVE-2022-22978
nomisec WRITEUP
by he-ewo · poc
https://github.com/he-ewo/CVE-2022-22978
nomisec WORKING POC
by wan9xx · poc
https://github.com/wan9xx/CVE-2022-22978-demo
nomisec WORKING POC
by Raghvendra1207 · poc
https://github.com/Raghvendra1207/CVE-2022-22978

Scores

CVSS v3 9.8
EPSS 0.9071
EPSS Percentile 99.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-863
Status published
Products (6)
netapp/active_iq_unified_manager (3 CPE variants)
oracle/financial_services_crime_and_compliance_management_studio 8.0.8.2.0
oracle/financial_services_crime_and_compliance_management_studio 8.0.8.3.0
org.springframework.security/spring-security-core 5.5.0 - 5.5.7Maven
org.springframework.security/spring-security-web 5.5.0 - 5.5.7Maven
vmware/spring_security < 5.5.7
Published May 19, 2022
Tracked Since Feb 18, 2026