Bug 2087274 (CVE-2022-22971)

Summary: CVE-2022-22971 springframework: DoS with STOMP over WebSocket
Product: [Other] Security Response Reporter: Guilherme de Almeida Suckevicz <gsuckevi>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: aboyko, aileenc, alazarot, anstephe, asoldano, ataylor, avibelli, bbaranow, bgeorges, bmaxwell, boliveir, brian.stansberry, cdewolf, chazlett, clement.escoffier, cmoulliard, dandread, darran.lofthouse, dchen, dkreling, dosoudil, drieden, emingora, etirelli, extras-orphan, fjuma, ggaughan, gmalinko, gsmet, hamadhan, hbraun, ibek, ikanello, iweiss, janstey, java-sig-commits, jnethert, jochrist, jolee, jrokos, jross, jschatte, jstastny, jwon, krathod, kverlaen, lgao, lthon, mnovotny, mokumar, mosmerov, msochure, msvehla, mszynkie, nwallace, pantinor, pdelbell, pdrozd, peholase, pgallagh, pjindal, pmackay, probinso, pskopek, puntogil, rareddy, rguimara, rkieley, rrajasek, rruss, rstancel, rsvoboda, sbiarozk, sdouglas, smaestri, sthorger, swoodman, tom.jenkinson, tzimanyi
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: springframework 5.3.20, springframework 5.2.22 Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in Spring Framework Applications. Applications that use STOMP over the WebSocket endpoint are vulnerable to a denial of service attack caused by an authenticated user.
Story Points: ---
Clone Of: Environment:
Last Closed: 2022-07-07 21:10:04 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2087275    
Bug Blocks: 2087215    

Description Guilherme de Almeida Suckevicz 2022-05-17 18:05:50 UTC
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.

Reference:
https://tanzu.vmware.com/security/cve-2022-22971

Comment 1 Guilherme de Almeida Suckevicz 2022-05-17 18:06:07 UTC
Created springframework tracking bugs for this issue:

Affects: fedora-all [bug 2087275]

Comment 3 errata-xmlrpc 2022-07-07 14:23:21 UTC
This issue has been addressed in the following products:

  Red Hat Fuse 7.11

Via RHSA-2022:5532 https://access.redhat.com/errata/RHSA-2022:5532

Comment 4 Product Security DevOps Team 2022-07-07 21:09:58 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2022-22971

Comment 8 errata-xmlrpc 2023-04-05 13:35:04 UTC
This issue has been addressed in the following products:

  AMQ Broker 7.11.0

Via RHSA-2023:1661 https://access.redhat.com/errata/RHSA-2023:1661

Comment 9 errata-xmlrpc 2023-05-17 13:58:52 UTC
This issue has been addressed in the following products:

  AMQ Broker 7.10.3

Via RHSA-2023:3185 https://access.redhat.com/errata/RHSA-2023:3185