A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.
{
"versions": [
{
"introduced": "0"
},
{
"fixed": "5.2.20"
},
{
"introduced": "5.3.0"
},
{
"fixed": "5.3.18"
},
{
"introduced": "0"
},
{
"last_affected": "3.0"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-22965.json"
[
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2.1.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.9.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "22.1.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.9.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "22.1.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "22.1.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.10.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "22.1.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.15.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "22.1.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.15.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "22.1.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.15.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "22.1.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.7.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "22.1.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.15.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "22.1.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12.6.0.0.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.1.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.1.2.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.1.1.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.1.1.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.1.2.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.1.1.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.1.1.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.1.2.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "8.0.29"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "3.6.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "20.0.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "21.0.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2.0.4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.80"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.85"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4.3.100"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4.3.200"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4.3.100"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4.3.200"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.0.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.0.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2.0.4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.2.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.0.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.80"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.85"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "11.3.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "22.1.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.5.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "16.0.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "17.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "18.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "19.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "14.1.3.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "15.0.3.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "16.0.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "19.0.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "14.1.3.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "15.0.3.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "16.0.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "19.0.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "16.0.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "19.0.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12.2.1.3.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12.2.1.4.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "14.1.1.0.0"
}
]
}
]