CVE-2022-22976
MEDIUM 5.3EPSS 2.3%
Spring Security versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, and earlier unsupported versions contain an integer overflow vulnerability. When using the BCrypt class with the maximum work factor (31), the encoder does not perform any salt rounds, due to an integer overflow error. The default settings are not affected by this CVE.
- CVSS v3.1
- 5.3 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N - CVSS v3.1
- 5.3 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N - CVSS v2.0
- 4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N - EPSS
- 2.34% chance of exploitation in the next 30 days, 82th percentile
- Published
- 2022-05-19
- Updated
- 2024-08-03
Proof-of-concept exploits (1)
- spring-io/cve-2022-22976-bcrypt-skips-salt1★ · 2022-05-10