In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-5219 In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.
Github GHSA Github GHSA GHSA-rqph-vqwm-22vc Allocation of Resources Without Limits or Throttling in Spring Framework
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.0039}

epss

{'score': 0.00444}


cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published:

Updated: 2024-08-03T03:28:42.583Z

Reserved: 2022-01-10T00:00:00

Link: CVE-2022-22971

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-05-12T20:15:15.110

Modified: 2024-11-21T06:47:43.027

Link: CVE-2022-22971

cve-icon Redhat

Severity : Moderate

Publid Date: 2022-05-11T00:00:00Z

Links: CVE-2022-22971 - Bugzilla

cve-icon OpenCVE Enrichment

No data.