Skip to content

CVE-2022-22968 @ Maven-org.springframework:spring-context-3.2.8.RELEASE #53

@igorlombacx

Description

@igorlombacx

Checkmarx (SCA): Vulnerable Package
Vulnerability: Read More about CVE-2022-22968
Checkmarx Project: igorlombacx/astlab2
Repository URL: https://github.com/igorlombacx/astlab2
Branch: main
Severity: MEDIUM
State: TO_VERIFY
Status: RECURRENT
Scan ID: 8caf1d69-ab69-4064-888d-abb555c4ebdc


In Spring Framework versions before 5.2.2.RELEASE, and 5.3.0 through 5.3.18, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with both upper and lower case for the first character of the field, including upper and lower case for the first character of all nested fields within the property path.


Additional Info
Attack vector: NETWORK
Attack complexity: LOW
Confidentiality impact: NONE
Availability impact: NONE
Remediation Upgrade Recommendation: 4.1.0.RC1

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions