Skip to content

CVE-2022-22976 @ Maven-org.springframework.security:spring-security-core-3.2.4.RELEASE #51

@igorlombacx

Description

@igorlombacx

Checkmarx (SCA): Vulnerable Package
Vulnerability: Read More about CVE-2022-22976
Checkmarx Project: igorlombacx/astlab2
Repository URL: https://github.com/igorlombacx/astlab2
Branch: main
Severity: MEDIUM
State: TO_VERIFY
Status: RECURRENT
Scan ID: 8caf1d69-ab69-4064-888d-abb555c4ebdc


Spring Security, modules "spring-security-core" and "spring-security-crypto", versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, and earlier unsupported versions contain an integer overflow vulnerability. When using the "BCrypt" class with the maximum work factor (31), the encoder does not perform any salt rounds, due to an integer overflow error. The default settings are not affected by this CVE.


Additional Info
Attack vector: NETWORK
Attack complexity: LOW
Confidentiality impact: LOW
Availability impact: NONE
Remediation Upgrade Recommendation: 4.0.0.M2

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions