Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2022-22970

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 52.8%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 3.5
Products affected by CVE-2022-22970


Contact Us

Shodan ® - All rights reserved