A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.
Is CVE-2022-22965 exploited?
Listed in the CISA KEV catalog on 2022-04-04.
Federal remediation due 2022-04-25.
Past that date by 1573 days.
EPSS puts exploitation in the next 30 days at 99.7%.
Public exploit code: packaged in a public tool.
Public detection rules exist.
Which products and versions are affected?
No affected package list recorded here yet.
Is there a patch?
No patch identifier recorded here yet.
What PlainSec published about CVE-2022-22965
PlainSec has not published a story about this CVE.