CVE-2022-22950 is a denial-of-service vulnerability affecting Spring Framework versions 5.3.0 through 5.3.16 and older unsupported versions. An authenticated attacker can exploit this by submitting a specially crafted SpEL expression, leading to a denial of service. While no public exploit code is available, the vulnerability has garnered significant community attention and media coverage, with some initial confusion surrounding its relation to the more critical "Spring4Shell" vulnerability. This medium-severity flaw (CVSS 6.5) does not appear to be actively exploited in the wild, and it is not listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.2.20CPE matchmatch criteria | cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:* | ||
>= 5.3.0, < 5.3.17CPE matchmatch criteria | cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.