Vulnerability CVE-2022-22970


Published: 2022-05-12

Description:
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.

 References:
https://tanzu.vmware.com/security/cve-2022-22970

Copyright 2026, cxsecurity.com

 

Back to Top