springframework: DoS with STOMP over WebSocket
Published May 12, 2022
6.5
MEDIUMCVSS 3.1
EPSS 3.17%
Description
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.
Affected products
- Vendor n/a Product Spring Framework Defaultn/a
- Version Spring Framework versions 5.3.x prior to 5.3.20, 5.2.x prior to 5.2.22 and all old and unsupported versionsStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Spring Framework | n/a |
|
Configuration 1
- ≥ 5.2.0 · ≤ 5.2.21
- ≥ 5.3.0 · ≤ 5.3.19
Configuration 2
- 8.0.8.2.0
- 8.0.8.3.0
Configuration 3
- n/a
- n/a
No data.
AMQ Broker 7.10.3
springframework
Fixed · RHSA-2023:3185
AMQ Broker 7.11.0
n/a
Fixed · RHSA-2023:1661
Red Hat Fuse 7.11
springframework
Fixed · RHSA-2022:5532
A-MQ Clients 2
springframework
Not affected
Red Hat Data Grid 8
springframework
Not affected
Red Hat Decision Manager 7
springframework
Fix deferred
Red Hat Integration Camel K 1
springframework
Not affected
Red Hat Integration Camel Quarkus 1
springframework
Not affected
Red Hat Integration Data Virtualisation Operator
springframework
Not affected
Red Hat JBoss BRMS 5
springframework
Out of support scope
Red Hat JBoss Data Grid 7
springframework
Out of support scope
Red Hat JBoss Data Virtualization 6
springframework
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
springframework
Out of support scope
Red Hat JBoss Enterprise Application Platform 7
springframework
Not affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
springframework
Not affected
Red Hat JBoss Fuse 6
springframework
Out of support scope
Red Hat JBoss Fuse Service Works 6
springframework
Out of support scope
Red Hat JBoss SOA Platform 5
springframework
Out of support scope
Red Hat Process Automation 7
springframework
Fix deferred
Red Hat Single Sign-On 7
springframework
Not affected
Red Hat build of Quarkus
springframework
Not affected
Red Hat support for Spring Boot
springframework
Out of support scope
streams for Apache Kafka
springframework
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| AMQ Broker 7.10.3 | springframework | Fixed | RHSA-2023:3185 |
| AMQ Broker 7.11.0 | n/a | Fixed | RHSA-2023:1661 |
| Red Hat Fuse 7.11 | springframework | Fixed | RHSA-2022:5532 |
| A-MQ Clients 2 | springframework | Not affected | n/a |
| Red Hat Data Grid 8 | springframework | Not affected | n/a |
| Red Hat Decision Manager 7 | springframework | Fix deferred | n/a |
| Red Hat Integration Camel K 1 | springframework | Not affected | n/a |
| Red Hat Integration Camel Quarkus 1 | springframework | Not affected | n/a |
| Red Hat Integration Data Virtualisation Operator | springframework | Not affected | n/a |
| Red Hat JBoss BRMS 5 | springframework | Out of support scope | n/a |
| Red Hat JBoss Data Grid 7 | springframework | Out of support scope | n/a |
| Red Hat JBoss Data Virtualization 6 | springframework | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | springframework | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | springframework | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | springframework | Not affected | n/a |
| Red Hat JBoss Fuse 6 | springframework | Out of support scope | n/a |
| Red Hat JBoss Fuse Service Works 6 | springframework | Out of support scope | n/a |
| Red Hat JBoss SOA Platform 5 | springframework | Out of support scope | n/a |
| Red Hat Process Automation 7 | springframework | Fix deferred | n/a |
| Red Hat Single Sign-On 7 | springframework | Not affected | n/a |
| Red Hat build of Quarkus | springframework | Not affected | n/a |
| Red Hat support for Spring Boot | springframework | Out of support scope | n/a |
| streams for Apache Kafka | springframework | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (11)
- https://access.redhat.com/security/cve/CVE-2022-22971 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2087274 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-5219 Advisory
- https://github.com/advisories/GHSA-rqph-vqwm-22vc Advisory
- https://github.com/spring-projects/spring-framework/commit/159a99bbafdd6c01871228113d7042c3f83f360f
- https://github.com/spring-projects/spring-framework/commit/dc2947c52df18d5e99cad03383f7d6ba13d031fd
- https://nvd.nist.gov/vuln/detail/CVE-2022-22971
- https://security.netapp.com/advisory/ntap-20220616-0003 x_refsource_CONFIRMThird Party Advisory
- https://tanzu.vmware.com/security/cve-2022-22971 x_refsource_MISCMitigationVendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-22971
- https://www.oracle.com/security-alerts/cpujul2022.html x_refsource_MISCPatchThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-22971 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2087274 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-5219 | Advisory | |
| https://github.com/advisories/GHSA-rqph-vqwm-22vc | Advisory | |
| https://github.com/spring-projects/spring-framework/commit/159a99bbafdd6c01871228113d7042c3f83f360f | ||
| https://github.com/spring-projects/spring-framework/commit/dc2947c52df18d5e99cad03383f7d6ba13d031fd | ||
| https://nvd.nist.gov/vuln/detail/CVE-2022-22971 | ||
| https://security.netapp.com/advisory/ntap-20220616-0003 | x_refsource_CONFIRMThird Party Advisory | |
| https://tanzu.vmware.com/security/cve-2022-22971 | x_refsource_MISCMitigationVendor Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-22971 | ||
| https://www.oracle.com/security-alerts/cpujul2022.html | x_refsource_MISCPatchThird Party Advisory |
Change history (0)
No recorded changes yet.