Spring Framework Vulnerability CVE-2022-22970Issue date: 21-09-2022
Affects versions: 15.1, 14.7, 13.4
Security Issue ID
Affected Product Version(s)
15.1.0, 14.7.8, 13.4.18, and all previous versions
A Spring MVC application that handles file uploads is vulnerable to DoS attack if it relies on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.
The problem has been recognized and patched. The fix is available in version starting from 5.3.20 or 5.2.22.
Customers are recommended to upgrade to the latest version. As of the time of writing, 15.1.1, 14.7.9 or 13.4.19