CVE-2022-22971

Description

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.386

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities are affected in Oracle WebLogic Server 12.2.1.3.0Windows
Multiple vulnerabilities are affected in Oracle WebLogic Server 12.2.1.4.0Windows
Multiple vulnerabilities are affected in Oracle WebLogic Server 14.1.1.0.0Windows
Vulnerabilities CVE-2022-22971 are fixed in spring-messaging 5.2.22Windows
Vulnerabilities CVE-2022-22971 are fixed in spring-messaging 5.3.20Windows
Multiple Vulnerabilities are affected in Netapp Oncommand Insight 2.3Windows
Multiple vulnerabilities are affected in Oracle Commerce Platform 11.3.2Windows
Vulnerabilities CVE-2022-22971 are fixed in spring-messaging for Linux 5.2.22Linux
Vulnerabilities CVE-2022-22971 are fixed in spring-messaging for Linux 5.3.20Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234