CVE-2022-22979: Spring Cloud Function Dos Vulnerability

HIGH | JUNE 15, 2022 | CVE-2022-22979
Description In Spring Cloud Function versions 3.2.5 and older unsupported versions, it is possible for a user who directly interacts with framework provided lookup functionality to cause denial of service condition due to the caching issue in Function Catalog…

CVE-2022-22976: BCrypt skips salt rounds for work factor of 31

MEDIUM | MAY 17, 2022 | CVE-2022-22976
Description Affected Spring Products and Versions Mitigation Credit This issue was identified and responsibly reported by Eyal Kaspi. References https://docs.spring.io/spring-security/site/docs/current/reference/html5/#authentication-password-storage https…

CVE-2022-22978: Authorization Bypass in RegexRequestMatcher

HIGH | MAY 16, 2022 | CVE-2022-22978
Description Affected Spring Products and Versions Mitigation Users should update to a version that includes fixes. 5.5.x users should upgrade to 5.5.7 or greater. 5.6.x users should upgrade to 5.6.4 or greater. Releases that have fixed this issue include…

Get ahead

VMware offers training and certification to turbo-charge your progress.

Learn more

Get support

Tanzu Spring offers support and binaries for OpenJDK™, Spring, and Apache Tomcat® in one simple subscription.

Learn more

Upcoming events

Check out all the upcoming events in the Spring community.

View all