Skip to content

CVE-2022-22971 @ Maven-org.springframework:spring-core-3.2.4.RELEASE #54

@igorlombacx

Description

@igorlombacx

Checkmarx (SCA): Vulnerable Package
Vulnerability: Read More about CVE-2022-22971
Checkmarx Project: igorlombacx/astlab2
Repository URL: https://github.com/igorlombacx/astlab2
Branch: main
Severity: MEDIUM
State: TO_VERIFY
Status: RECURRENT
Scan ID: 8caf1d69-ab69-4064-888d-abb555c4ebdc


In Spring Framework versions 5.2.0 through 5.2.21, 5.3.0 through 5.3.19, and older unsupported versions, application with a "STOMP" over "WebSocket" endpoint is vulnerable to a Denial of Service attack by an authenticated user.


Additional Info
Attack vector: NETWORK
Attack complexity: LOW
Confidentiality impact: NONE
Availability impact: HIGH
Remediation Upgrade Recommendation: 4.0.0.M3

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions