Spring Framework Vulnerability CVE-2022-22970
Issue date: 21-09-2022Affects versions: 15.1, 14.7, 13.4
Security Issue ID
SECURITY-362
Affected Product Version(s)
15.1.0, 14.7.8, 13.4.18, and all previous versions
Severity
Medium
Description
A Spring MVC application that handles file uploads is vulnerable to DoS attack if it relies on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.
The problem has been recognized and patched. The fix is available in version starting from 5.3.20 or 5.2.22.
Instructions
Customers are recommended to upgrade to the latest version. As of the time of writing, 15.1.1, 14.7.9 or 13.4.19