springframework: BCrypt skips salt rounds for work factor of 31
Published May 19, 2022
5.3
MEDIUMCVSS 3.1
EPSS 2.34%
Description
Spring Security versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, and earlier unsupported versions contain an integer overflow vulnerability. When using the BCrypt class with the maximum work factor (31), the encoder does not perform any salt rounds, due to an integer overflow error. The default settings are not affected by this CVE.
Affected products
- Vendor n/a Product Spring Security Defaultn/a
- Version Spring Security versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, and earlier unsupported versionsStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Spring Security | n/a |
|
Configuration 1
- ≥ 5.2.1 · < 5.5.7
- ≥ 5.6.0 · < 5.6.4
- 5.2.0
Configuration 2
- 8.0.8.2.0
- 8.0.8.3.0
Configuration 3
- n/a
- n/a
- n/a
No data.
OpenShift Developer Tools and Services for OCP 4.11
jenkins-0:2.401.1.1686831596-3.el8
Fixed · RHSA-2023:3663
Red Hat Fuse 7.11
spring-security
Fixed · RHSA-2022:5532
A-MQ Clients 2
springframework
Not affected
Red Hat Data Grid 8
springframework
Not affected
Red Hat Decision Manager 7
springframework
Fix deferred
Red Hat Integration Camel K 1
springframework
Not affected
Red Hat Integration Camel Quarkus 1
springframework
Not affected
Red Hat Integration Data Virtualisation Operator
springframework
Out of support scope
Red Hat JBoss BRMS 5
springframework
Out of support scope
Red Hat JBoss Data Grid 7
springframework
Out of support scope
Red Hat JBoss Data Virtualization 6
springframework
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
springframework
Out of support scope
Red Hat JBoss Enterprise Application Platform 7
springframework
Not affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
springframework
Not affected
Red Hat JBoss Fuse 6
springframework
Out of support scope
Red Hat JBoss Fuse Service Works 6
springframework
Out of support scope
Red Hat JBoss SOA Platform 5
springframework
Out of support scope
Red Hat OpenShift Container Platform 3.11
jenkins
Out of support scope
Red Hat OpenShift Container Platform 4
jenkins
Not affected
Red Hat Process Automation 7
springframework
Fix deferred
Red Hat Single Sign-On 7
springframework
Not affected
Red Hat build of Quarkus
springframework
Not affected
Red Hat support for Spring Boot
springframework
Not affected
streams for Apache Kafka
springframework
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenShift Developer Tools and Services for OCP 4.11 | jenkins-0:2.401.1.1686831596-3.el8 | Fixed | RHSA-2023:3663 |
| Red Hat Fuse 7.11 | spring-security | Fixed | RHSA-2022:5532 |
| A-MQ Clients 2 | springframework | Not affected | n/a |
| Red Hat Data Grid 8 | springframework | Not affected | n/a |
| Red Hat Decision Manager 7 | springframework | Fix deferred | n/a |
| Red Hat Integration Camel K 1 | springframework | Not affected | n/a |
| Red Hat Integration Camel Quarkus 1 | springframework | Not affected | n/a |
| Red Hat Integration Data Virtualisation Operator | springframework | Out of support scope | n/a |
| Red Hat JBoss BRMS 5 | springframework | Out of support scope | n/a |
| Red Hat JBoss Data Grid 7 | springframework | Out of support scope | n/a |
| Red Hat JBoss Data Virtualization 6 | springframework | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | springframework | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | springframework | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | springframework | Not affected | n/a |
| Red Hat JBoss Fuse 6 | springframework | Out of support scope | n/a |
| Red Hat JBoss Fuse Service Works 6 | springframework | Out of support scope | n/a |
| Red Hat JBoss SOA Platform 5 | springframework | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 3.11 | jenkins | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 4 | jenkins | Not affected | n/a |
| Red Hat Process Automation 7 | springframework | Fix deferred | n/a |
| Red Hat Single Sign-On 7 | springframework | Not affected | n/a |
| Red Hat build of Quarkus | springframework | Not affected | n/a |
| Red Hat support for Spring Boot | springframework | Not affected | n/a |
| streams for Apache Kafka | springframework | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (11)
- https://access.redhat.com/security/cve/CVE-2022-22976 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2087214 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-5665 Advisory
- https://github.com/advisories/GHSA-wx54-3278-m5g4 Advisory
- https://github.com/spring-projects/spring-security/commit/388a7b62b906bd56deadb7ca45248fa1a63bdf12
- https://github.com/spring-projects/spring-security/commit/a40f73521c0dd88b879ff6165d280e78bdf8154f
- https://nvd.nist.gov/vuln/detail/CVE-2022-22976
- https://security.netapp.com/advisory/ntap-20220707-0003 x_refsource_CONFIRMThird Party Advisory
- https://tanzu.vmware.com/security/cve-2022-22976 x_refsource_MISCMitigationVendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-22976
- https://www.oracle.com/security-alerts/cpujul2022.html x_refsource_MISCPatchThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-22976 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2087214 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-5665 | Advisory | |
| https://github.com/advisories/GHSA-wx54-3278-m5g4 | Advisory | |
| https://github.com/spring-projects/spring-security/commit/388a7b62b906bd56deadb7ca45248fa1a63bdf12 | ||
| https://github.com/spring-projects/spring-security/commit/a40f73521c0dd88b879ff6165d280e78bdf8154f | ||
| https://nvd.nist.gov/vuln/detail/CVE-2022-22976 | ||
| https://security.netapp.com/advisory/ntap-20220707-0003 | x_refsource_CONFIRMThird Party Advisory | |
| https://tanzu.vmware.com/security/cve-2022-22976 | x_refsource_MISCMitigationVendor Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-22976 | ||
| https://www.oracle.com/security-alerts/cpujul2022.html | x_refsource_MISCPatchThird Party Advisory |
Change history (0)
No recorded changes yet.