VMSA-2022-0014
VMSA-2022-0014: Questions & Answers
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.
The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.
VMSA-2022-0014: Questions & Answers
Authorization bypass in Spring Security
CVEs:GHSA-hh32-7344-cg2f
Authorization bypass in Spring Security
CVEs:CVE-2022-22978
Allocation of Resources Without Limits or Throttling in Spring Framework
CVEs:GHSA-rqph-vqwm-22vc
Allocation of Resources Without Limits or Throttling in Spring Framework
CVEs:CVE-2022-22971
Integer overflow in BCrypt class in Spring Security
CVEs:GHSA-wx54-3278-m5g4
Integer overflow in BCrypt class in Spring Security
CVEs:CVE-2022-22976
GHSA-6q84-cfgm-7vcv
CVEs:GHSA-6q84-cfgm-7vcv
Denial of service in Spring Framework
CVEs:GHSA-hh26-6xwr-ggv7
Denial of service in Spring Framework
CVEs:CVE-2022-22970
Improper Output Neutralization for Logs in Spring Framework
CVEs:GHSA-rfmp-97jj-h8m6
GHSA-2mjv-62fw-hvv4
CVEs:GHSA-2mjv-62fw-hvv4
CVEs:CVE-2021-22117
GHSA-rwr9-36p6-24vw
CVEs:GHSA-rwr9-36p6-24vw
Improper Privilege Management in Spring Framework
CVEs:GHSA-gfwj-fwqj-fp3v
GHSA-4rmm-hmcx-2hg3
CVEs:GHSA-4rmm-hmcx-2hg3
Improper Neutralization of Input During Web Page Generation in Spring Framework
CVEs:GHSA-xjrf-8x4f-43h4
GHSA-9rmg-8r3f-xrq7
CVEs:GHSA-9rmg-8r3f-xrq7
GHSA-2wpx-p7qg-954w
CVEs:GHSA-2wpx-p7qg-954w
CVEs:CVE-2020-5396
GHSA-3g3v-fjwj-v857
CVEs:GHSA-3g3v-fjwj-v857
Deserialization of Untrusted Data in Spring Batch
CVEs:CVE-2020-5411
Deserialization of Untrusted Data in Spring Batch
CVEs:GHSA-4ph4-q9r5-6wm6
GHSA-829v-ph86-cw55
CVEs:GHSA-829v-ph86-cw55
GHSA-973v-v8wv-cw5w
CVEs:GHSA-973v-v8wv-cw5w
GHSA-6c8m-9r93-f9rp
CVEs:GHSA-6c8m-9r93-f9rp
GHSA-q4p6-fc6x-phmp
CVEs:GHSA-q4p6-fc6x-phmp
Cloud Foundry UAA Privilege Escalation
CVEs:GHSA-292x-hjr8-226f
GHSA-4gr5-536m-w65f
CVEs:GHSA-4gr5-536m-w65f
GHSA-wqw3-2xp4-g8h7
CVEs:GHSA-wqw3-2xp4-g8h7
Cloud Foundry denial of service vulnerability
CVEs:GHSA-hxgw-7539-pv7r
GHSA-hj4v-mrqp-x329
CVEs:GHSA-hj4v-mrqp-x329
GHSA-rr6c-mf52-hvf4
CVEs:GHSA-rr6c-mf52-hvf4
GHSA-rj7c-vg4r-rx5m
CVEs:GHSA-rj7c-vg4r-rx5m
GHSA-mf6g-2h9h-jw37
CVEs:GHSA-mf6g-2h9h-jw37
GHSA-w2x8-37g8-j83c
CVEs:GHSA-w2x8-37g8-j83c
GHSA-g54m-6fph-847q
CVEs:GHSA-g54m-6fph-847q
GHSA-hp2f-4chh-4499
CVEs:GHSA-hp2f-4chh-4499
GHSA-9235-9qc9-8p4j
CVEs:GHSA-9235-9qc9-8p4j
GHSA-5hjq-8gx9-79g4
CVEs:GHSA-5hjq-8gx9-79g4
GHSA-5hx9-w49q-v9p8
CVEs:GHSA-5hx9-w49q-v9p8
GHSA-6c72-gqp5-jh4r
CVEs:GHSA-6c72-gqp5-jh4r
GHSA-9hx4-42jp-5rgc
CVEs:GHSA-9hx4-42jp-5rgc
UAA privilege escalation across identity zones
CVEs:GHSA-8v97-gv3g-32rf
GHSA-272q-hvx6-q97c
CVEs:GHSA-272q-hvx6-q97c
GHSA-q96c-r8j3-g2qp
CVEs:GHSA-q96c-r8j3-g2qp
GHSA-75vm-6gpr-f398
CVEs:GHSA-75vm-6gpr-f398
GHSA-vc7q-m69g-gmvq
CVEs:GHSA-vc7q-m69g-gmvq
GHSA-m392-rj9c-4gwh
CVEs:GHSA-m392-rj9c-4gwh
GHSA-gv3c-929j-rc7p
CVEs:GHSA-gv3c-929j-rc7p
GHSA-84j7-fm4m-279g
CVEs:GHSA-84j7-fm4m-279g
GHSA-9j8m-7rpr-659f
CVEs:GHSA-9j8m-7rpr-659f
GHSA-jf63-p3cp-7qf7
CVEs:GHSA-jf63-p3cp-7qf7
GHSA-hpg7-3mv4-7gc8
CVEs:GHSA-hpg7-3mv4-7gc8
Cloud Foundry UAA privilege escalation with user invitations
CVEs:GHSA-jcmh-x32v-7mgf
GHSA-8pj8-jjrc-8g8h
CVEs:GHSA-8pj8-jjrc-8g8h
GHSA-6q7m-3j88-7g48
CVEs:GHSA-6q7m-3j88-7g48
GHSA-9jcx-c729-r5q2
CVEs:GHSA-9jcx-c729-r5q2
GHSA-f5h8-wfwr-29f4
CVEs:GHSA-f5h8-wfwr-29f4
GHSA-jj4c-53qh-fp5v
CVEs:GHSA-jj4c-53qh-fp5v
GHSA-cgmm-ggpv-874w
CVEs:GHSA-cgmm-ggpv-874w
GHSA-932h-8mcc-v5m6
CVEs:GHSA-932h-8mcc-v5m6
GHSA-75xv-v35m-f8rh
CVEs:GHSA-75xv-v35m-f8rh
GHSA-7rf4-2hjj-cg48
CVEs:GHSA-7rf4-2hjj-cg48
GHSA-2rm2-vwh2-fp52
CVEs:GHSA-2rm2-vwh2-fp52
Cloud Foundry UAA Denial of Service through client token revocation endpoint
CVEs:GHSA-j4p3-2m2h-cv5f
GHSA-5w93-xgv6-rpgw
CVEs:GHSA-5w93-xgv6-rpgw
GHSA-rqq3-c3q5-mfrg
CVEs:GHSA-rqq3-c3q5-mfrg
Cloud Foundry UAA Privilege Escalation
CVEs:GHSA-pgjc-gc7g-p2c6
Cloud Foundry UAA accepts refresh token as access token on admin endpoints
CVEs:GHSA-r4v8-9hgx-vm6m
Exposure of Resource to Wrong Sphere in Spring Cloud OpenFeign
CVEs:CVE-2021-22044
Exposure of Resource to Wrong Sphere in Spring Cloud OpenFeign
CVEs:GHSA-pf94-6v2v-cm3j
GHSA-62q3-rvgv-rchp
CVEs:GHSA-62q3-rvgv-rchp
GHSA-7mqj-h5x5-v4fc
CVEs:GHSA-7mqj-h5x5-v4fc
GHSA-rq2f-rgc6-gfh9
CVEs:GHSA-rq2f-rgc6-gfh9
GHSA-g4rj-4g63-8r2h
CVEs:GHSA-g4rj-4g63-8r2h
Deserialization of Untrusted Data in Spring AMQP
CVEs:CVE-2021-22097
Deserialization of Untrusted Data in Spring AMQP
CVEs:GHSA-fx7f-rjqj-52pj
CVEs:CVE-2020-5401
GHSA-jgr4-5mrv-w8ph
CVEs:GHSA-jgr4-5mrv-w8ph
GHSA-c8h4-2c59-gmm5
CVEs:GHSA-c8h4-2c59-gmm5
Cloud Foundry UAA SessionID present in Audit Event Logs
CVEs:GHSA-xg5v-696h-c3vr
GHSA-3gw8-xrcq-5xfv
CVEs:GHSA-3gw8-xrcq-5xfv
CVEs:CVE-2020-5406
GHSA-vr33-39v9-jw2c
CVEs:GHSA-vr33-39v9-jw2c
GHSA-j3cm-76qq-2qmp
CVEs:GHSA-j3cm-76qq-2qmp
GHSA-mxfj-x685-fxwf
CVEs:GHSA-mxfj-x685-fxwf
GHSA-7g7m-r288-q7h8
CVEs:GHSA-7g7m-r288-q7h8
GHSA-w6j8-5rqh-gxwv
CVEs:GHSA-w6j8-5rqh-gxwv
GHSA-8f73-86rh-w9fj
CVEs:GHSA-8f73-86rh-w9fj
GHSA-jq2q-gqc9-53g3
CVEs:GHSA-jq2q-gqc9-53g3
Blind SQL Injection with privileged Cloud Foundry UAA endpoints
CVEs:GHSA-cw9c-v3v2-99hm
GHSA-w6w3-q7mh-r859
CVEs:GHSA-w6w3-q7mh-r859
GHSA-cjhg-rj52-r938
CVEs:GHSA-cjhg-rj52-r938
GHSA-3w28-fqx3-7jv2
CVEs:GHSA-3w28-fqx3-7jv2
GHSA-gfwv-5245-24h8
CVEs:GHSA-gfwv-5245-24h8
GHSA-6cf2-hv75-pxf8
CVEs:GHSA-6cf2-hv75-pxf8
Cloud Foundry UAA password reset vulnerability
CVEs:GHSA-cgrg-x34r-78f3
GHSA-gmr3-mrrf-r3v7
CVEs:GHSA-gmr3-mrrf-r3v7
GHSA-wxfx-g5v8-gmxf
CVEs:GHSA-wxfx-g5v8-gmxf
CVEs:CVE-2020-5422
GHSA-v9qc-85w7-58x4
CVEs:GHSA-v9qc-85w7-58x4
GHSA-v3fx-g84p-g838
CVEs:GHSA-v3fx-g84p-g838
GHSA-gqg8-8x59-r3xm
CVEs:GHSA-gqg8-8x59-r3xm
Cloud Foundry UAA Identity Zone Admin Privilege Escalation
CVEs:GHSA-9frw-wmvq-5rrc
GHSA-hwg9-rc2h-c2p3
CVEs:GHSA-hwg9-rc2h-c2p3
Cloud Foundry UAA open redirect
CVEs:GHSA-xh4m-99qp-w483
CVEs:CVE-2021-22115
GHSA-vhwm-f423-2fx6
CVEs:GHSA-vhwm-f423-2fx6
GHSA-qf8p-gpw6-r52g
CVEs:GHSA-qf8p-gpw6-r52g
Pivotal Cloud Foundry UAA XSS on UAA OpenID Connect check session iframe endpoint
CVEs:GHSA-j97q-9xp9-g5fx
GHSA-q3c3-832g-jxjc
CVEs:GHSA-q3c3-832g-jxjc
GHSA-398j-r5c5-vrph
CVEs:GHSA-398j-r5c5-vrph
GHSA-2443-wh6v-5rjf
CVEs:GHSA-2443-wh6v-5rjf
GHSA-r999-j7hp-qmgq
CVEs:GHSA-r999-j7hp-qmgq
CVEs:CVE-2020-5400
GHSA-m9cq-wcff-6m72
CVEs:GHSA-m9cq-wcff-6m72
GHSA-47fq-mm42-6v8w
CVEs:GHSA-47fq-mm42-6v8w
Exposure of Resource to Wrong Sphere in Spring Data REST
CVEs:CVE-2021-22047
Exposure of Resource to Wrong Sphere in Spring Data REST
CVEs:GHSA-4926-qpxg-6r3w
CVEs:CVE-2020-5425
GHSA-vmxh-mp6w-252x
CVEs:GHSA-vmxh-mp6w-252x
CVEs:CVE-2021-22098
GHSA-gmmg-mg5x-45rp
CVEs:GHSA-gmmg-mg5x-45rp
GHSA-xx5w-cqxh-w2m4
CVEs:GHSA-xx5w-cqxh-w2m4
GHSA-3cvg-mw7q-93pw
CVEs:GHSA-3cvg-mw7q-93pw
CVEs:CVE-2020-5414
GHSA-6p3r-vmr8-vfcg
CVEs:GHSA-6p3r-vmr8-vfcg
GHSA-xvcr-4h4q-m7m8
CVEs:GHSA-xvcr-4h4q-m7m8
GHSA-pw4q-58pr-v79g
CVEs:GHSA-pw4q-58pr-v79g
GHSA-5mjc-xm4w-8h63
CVEs:GHSA-5mjc-xm4w-8h63
GHSA-xr6m-h5m8-p48r
CVEs:GHSA-xr6m-h5m8-p48r
GHSA-4w8g-vwqf-w48w
CVEs:GHSA-4w8g-vwqf-w48w
GHSA-vv4h-5633-8243
CVEs:GHSA-vv4h-5633-8243
GHSA-84x8-jf5h-4974
CVEs:GHSA-84x8-jf5h-4974
CVEs:CVE-2020-5399
GHSA-w39h-6cmp-6crw
CVEs:GHSA-w39h-6cmp-6crw
CVEs:CVE-2020-5402
GHSA-5fqw-8f7q-58m9
CVEs:GHSA-5fqw-8f7q-58m9
GHSA-hhx3-g956-h93h
CVEs:GHSA-hhx3-g956-h93h
GHSA-4w69-xg22-fccq
CVEs:GHSA-4w69-xg22-fccq
GHSA-82gq-g626-8g5r
CVEs:GHSA-82gq-g626-8g5r
GHSA-3vvh-rcx9-vcx3
CVEs:GHSA-3vvh-rcx9-vcx3
GHSA-8jpp-7p79-w764
CVEs:GHSA-8jpp-7p79-w764
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.