CVE-2022-22950

MEDIUM6.5EPSS 2.5%

Allocation of Resources Without Limits or Throttling in Spring Framework

Published: 4/3/2022Modified: 11/8/2023
Also known as:GHSA-558x-2xjg-6232

Description

In Spring Framework versions 5.3.0 - 5.3.16, 5.2.0.RELEASE - 5.2.19.RELEASE, and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.5CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

References (9)