Medium severity5.3NVD Advisory· Published Apr 14, 2022· Updated Jun 17, 2026
CVE-2022-22968
CVE-2022-22968
Description
In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with both upper and lower case for the first character of the field, including upper and lower case for the first character of all nested fields within the property path.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.springframework:spring-contextMaven | >= 5.3.0, < 5.3.19 | 5.3.19 |
org.springframework:spring-contextMaven | < 5.2.21.RELEASE | 5.2.21.RELEASE |
Affected products
12cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*+ 2 more
- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*
- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*
- cpe:2.3:a:netapp:cloud_secure_agent:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:metrocluster_tiebreaker:-:*:*:*:*:clustered_data_ontap:*:*
- cpe:2.3:a:netapp:snap_creator_framework:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:snapmanager:-:*:*:*:*:oracle:*:*+ 1 more
- cpe:2.3:a:netapp:snapmanager:-:*:*:*:*:oracle:*:*
- cpe:2.3:a:netapp:snapmanager:-:*:*:*:*:sap:*:*
- cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:*Range: <=8.0.29
Patches
Vulnerability mechanics
References
8- github.com/advisories/GHSA-g5mm-vmx4-3rg7ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-22968ghsaADVISORY
- security.netapp.com/advisory/ntap-20220602-0004/nvdThird Party Advisory
- tanzu.vmware.com/security/cve-2022-22968nvdVendor AdvisoryWEB
- www.oracle.com/security-alerts/cpujul2022.htmlnvdThird Party AdvisoryWEB
- github.com/spring-projects/spring-framework/commit/833e750175349ab4fd502109a8b41af77e25cdeaghsaWEB
- github.com/spring-projects/spring-framework/commit/a7cf19cec5ebd270f97a194d749e2d5701ad2ab7ghsaWEB
- security.netapp.com/advisory/ntap-20220602-0004ghsaWEB
News mentions
0No linked articles in our index yet.