← Back to CVE List

CVE-2022-22970

Published: 2022-05-12T20:15Z
Last Modified: 2024-11-21T06:47Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt