Miggo Logo

CVE-2021-22118:
Improper Privilege Management in Spring Framework

7.8

CVSS Score
3.1

Basic Information

EPSS Score
0.48585%
Published
5/24/2022
Updated
7/19/2023
KEV Status
No
Technology
TechnologyJava

Technical Details

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Package NameEcosystemVulnerable VersionsFirst Patched Version
org.springframework:spring-webmaven>= 5.2.0, <= 5.2.145.2.15
org.springframework:spring-webmaven>= 5.3.0, <= 5.3.65.3.7

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

In Sprin* *r*m*work, v*rsions *.*.x prior to *.*.** *n* v*rsions *.*.x prior to *.*.*, * W***lux *ppli**tion is vuln*r**l* to * privil*** *s**l*tion: *y (r*)*r**tin* t** t*mpor*ry stor*** *ir**tory, * lo**lly *ut**nti**t** m*li*ious us*r **n r*** or

Reasoning

No *n*lysis *v*il**l*