CVE-2022-22980 PUBLISHED

n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition.

EPSS 83.37% · 99.3th percentile

Risk Scores

EPSS Score
83.37%
99.3th percentile

Affected Products

VendorProductVersions
n/aSpring FrameworkSpring Framework versions 5.3.X prior to 5.3.17+ and all old and unsupported versions

Timeline

References

Open in Interactive Console →