CVE-2025-22233 is a low-severity vulnerability affecting Spring Framework versions 5.3.x, 6.0.x, 6.1.x, and 6.2.x, allowing bypass of disallowedFields checks despite previous locale-independent lowercase conversion. The attack vector is network-based with high attack complexity, requiring low privileges, and can lead to low integrity impact without affecting confidentiality or availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.3.0, <= 5.3.42CPE match | cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:* | ||
>= 6.0.0, <= 6.0.27CPE match | cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:* | ||
>= 6.1.0, <= 6.1.19CPE match | cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:* | ||
>= 6.2.0, <= 6.2.6CPE match | cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.