Description
n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition.
Remediation
References
https://tanzu.vmware.com/security/cve-2022-22950
Related Vulnerabilities
CVE-2021-21612 Vulnerability in maven package de.tracetronic.jenkins.plugins:ecutest
CVE-2022-25205 Vulnerability in maven package org.jenkins-ci.plugins:dbcharts
CVE-2020-10714 Vulnerability in maven package org.wildfly.security:wildfly-elytron
CVE-2020-28052 Vulnerability in maven package org.bouncycastle:bcprov-jdk15on
CVE-2022-1278 Vulnerability in maven package org.wildfly:wildfly-microprofile