forked from cx-vered-shahar/astlab2
-
Notifications
You must be signed in to change notification settings - Fork 0
Open
Description
Checkmarx (SCA): Vulnerable Package
Vulnerability: Read More about CVE-2022-22970
Checkmarx Project: igorlombacx/astlab2
Repository URL: https://github.com/igorlombacx/astlab2
Branch: main
Severity: MEDIUM
State: TO_VERIFY
Status: RECURRENT
Scan ID: 8caf1d69-ab69-4064-888d-abb555c4ebdc
In Spring Framework versions 5.2.0 through 5.2.21, 5.3.0 through 5.3.19, and older unsupported versions, applications that handle file uploads are vulnerable to DoS attacks if they rely on data binding to set a "MultipartFile" or "javax.servlet.Part" to a "field" in a model object.
Additional Info
Attack vector: NETWORK
Attack complexity: HIGH
Confidentiality impact: NONE
Availability impact: HIGH
Remediation Upgrade Recommendation: 4.1.0.RC1
Reactions are currently unavailable