Denial of Service Vulnerability in Spring Framework by VMware
CVE-2022-22970
What is CVE-2022-22970?
A vulnerability exists in the Spring Framework that allows applications handling file uploads to be susceptible to Denial of Service (DoS) attacks. This issue arises when applications utilize data binding to assign a MultipartFile or javax.servlet.Part to a model object. Versions of the Spring Framework prior to 5.3.20 and 5.2.22, as well as other old, unsupported versions, are inherently at risk, making it crucial for users to update to secure versions to mitigate potential abuse.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Spring Framework Spring Framework versions 5.3.x prior to 5.3.20, 5.2.x prior to 5.2.22 and all old and unsupported versions
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved