VMSA-2022-0011
VMSA-2022-0011: Questions & Answers
CVEs:CVE-2022-22954CVE-2022-22955CVE-2022-22956CVE-2022-22957CVE-2022-22958CVE-2022-22959CVE-2022-22960CVE-2022-22961
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 2 are already weaponised in the wild — see the Exploited section.
The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.
VMSA-2022-0011: Questions & Answers
CVEs:CVE-2022-22954CVE-2022-22955CVE-2022-22956CVE-2022-22957CVE-2022-22958CVE-2022-22959CVE-2022-22960CVE-2022-22961
Spring Cloud Function Code Injection with a specially crafted SpEL as a routing expression
CVEs:GHSA-6v73-fgf6-w5j7
Allocation of Resources Without Limits or Throttling in Spring Framework
CVEs:GHSA-558x-2xjg-6232
Improper handling of case sensitivity in Spring Framework
CVEs:GHSA-g5mm-vmx4-3rg7
Improper handling of case sensitivity in Spring Framework
CVEs:CVE-2022-22968
Denial of service in Spring Security OAuth2
CVEs:GHSA-c2cp-3xj9-97w9
Denial of service in Spring Security OAuth2
CVEs:CVE-2022-22969
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.