VDB
DEBIAN-CVE-2022-22968
DEBIAN-CVE-2022-22968
PUBLISHED
CVSS 5.300000190734863 MEDIUM
In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with both upper and lower case for the first character of the field, including upper and lower case for the first character of all nested fields within the property path.
Risk Scores
CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:14 | libspring-java | 0, 4.3.30-3, 4.3.30-4 |
| Debian:11 | libspring-java | 4.3.30-2, 0, 4.3.30-1 |
| Debian:12 | libspring-java | 4.3.30-3, 4.3.30-4, 0 |
| Debian:13 | libspring-java | 4.3.30-3, 0, 0 |
Exploit Intelligence
- Testing CVE-2022-22968 (github-poc)
- dimage.html (github-poc)
- dependency-check-suppress.xml (github-poc)
Timeline
- Apr 14, 2022 CVE Published
- Apr 28, 2026 CVE Updated