Loading HuntDB...

CVE-2022-22968

UNKNOWN
Published 2022-04-14T20:05:50
Actions:

Expert Analysis

Professional remediation guidance

Get tailored security recommendations from our analyst team for CVE-2022-22968. We'll provide specific mitigation strategies based on your environment and risk profile.

No CVSS data available

Description

In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with both upper and lower case for the first character of the field, including upper and lower case for the first character of all nested fields within the property path.

Available Exploits

No exploits available for this CVE.

Related News

No news articles found for this CVE.

GitHub Security Advisories

Community-driven vulnerability intelligence from GitHub

✓ GitHub Reviewed HIGH

Improper handling of case sensitivity in Spring Framework

GHSA-g5mm-vmx4-3rg7

Advisory Details

In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with both upper and lower case for the first character of the field, including upper and lower case for the first character of all nested fields within the property path. Versions 5.3.19 and 5.2.21 contain a patch for this issue.

Affected Packages

Maven org.springframework:spring-context
ECOSYSTEM: ≥5.3.0 <5.3.19
Maven org.springframework:spring-context
ECOSYSTEM: ≥0 <5.2.21.RELEASE

CVSS Scoring

CVSS Score

7.5

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Advisory provided by GitHub Security Advisory Database. Published: April 15, 2022, Modified: May 15, 2024

References

Published: 2022-04-14T20:05:50
Last Modified: 2024-08-03T03:28:42.847Z
Copied to clipboard!