Vulnerability Description
Applications that allow HTTP PATCH access to resources exposed by Spring Data REST in versions 3.6.0 - 3.5.5, 3.7.0 - 3.7.2, and older unsupported versions, if an attacker knows about the structure of the underlying domain model, they can craft HTTP requests that expose hidden entity attributes.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Spring Data Rest | >= 3.6.0, < 3.6.7 |
References
- https://tanzu.vmware.com/security/cve-2022-31679Vendor Advisory
- https://tanzu.vmware.com/security/cve-2022-31679Vendor Advisory
FAQ
What is CVE-2022-31679?
CVE-2022-31679 is a vulnerability with a CVSS score of 3.7 (LOW). Applications that allow HTTP PATCH access to resources exposed by Spring Data REST in versions 3.6.0 - 3.5.5, 3.7.0 - 3.7.2, and older unsupported versions, if an attacker knows about the structure of...
How severe is CVE-2022-31679?
CVE-2022-31679 has been rated LOW with a CVSS base score of 3.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-31679?
Check the references section above for vendor advisories and patch information. Affected products include: Vmware Spring Data Rest.