In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object. Reference: https://tanzu.vmware.com/security/cve-2022-22970
Created springframework tracking bugs for this issue: Affects: fedora-all [bug 2087273]
This issue has been addressed in the following products: Red Hat Fuse 7.11 Via RHSA-2022:5532 https://access.redhat.com/errata/RHSA-2022:5532
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2022-22970
This issue has been addressed in the following products: AMQ Broker 7.11.0 Via RHSA-2023:1661 https://access.redhat.com/errata/RHSA-2023:1661
This issue has been addressed in the following products: AMQ Broker 7.10.3 Via RHSA-2023:3185 https://access.redhat.com/errata/RHSA-2023:3185