CVE-2025-22233
Last modified
CVE-2025-22233 is a low-severity vulnerability rated 3.1/10 on the CVSS scale. CVE-2024-38820 ensured Locale-independent, lowercase conversion for both the configured disallowedFields patterns and for request parameter names. However, there are still cases where it is possible to bypass the disallowedFields checks. Affected Spring Products and Versions Spring Framework: * 6.2.0 - 6.2.6 * 6.1.0 - 6.1.19 * 6.0.0 - 6.0.27 * 5.3.0 - 5.3.42 * Older, unsupported versions are also affected Mitigation Users of affected versions should upgrade to the corresponding fixed version. Affected version(s)Fix Version Availability 6.2.x 6.2.7 OSS6.1.x 6.1.20 OSS6.0.x 6.0.28 Commercial https://enterprise.spring.io/ 5.3.x 5.3.43 Commercial https://enterprise.spring.io/ No further mitigation steps are necessary. Generally, we recommend using a dedicated model object with properties only for data binding, or using constructor binding since constructor arguments explicitly declare what to bind together with turning off setter binding through the declarativeBinding flag. EPSS estimates a 0.35% chance of exploitation in the next 30 days.
Description
CVE-2024-38820 ensured Locale-independent, lowercase conversion for both the configured disallowedFields patterns and for request parameter names. However, there are still cases where it is possible to bypass the disallowedFields checks. Affected Spring Products and Versions Spring Framework: * 6.2.0 - 6.2.6 * 6.1.0 - 6.1.19 * 6.0.0 - 6.0.27 * 5.3.0 - 5.3.42 * Older, unsupported versions are also affected Mitigation Users of affected versions should upgrade to the corresponding fixed version. Affected version(s)Fix Version Availability 6.2.x 6.2.7 OSS6.1.x 6.1.20 OSS6.0.x 6.0.28 Commercial https://enterprise.spring.io/ 5.3.x 5.3.43 Commercial https://enterprise.spring.io/ No further mitigation steps are necessary. Generally, we recommend using a dedicated model object with properties only for data binding, or using constructor binding since constructor arguments explicitly declare what to bind together with turning off setter binding through the declarativeBinding flag. See the Model Design section in the reference documentation. For setting binding, prefer the use of allowedFields (an explicit list) over disallowedFields. Credit This issue was responsibly reported by the TERASOLUNA Framework Development Team from NTT DATA Group Corporation.
Metrics
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-22233?
How severe is CVE-2025-22233?
How do I fix CVE-2025-22233?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-22227In some specific scenarios with chained redirects, Reactor N…6.1
- CVE-2025-22228BCryptPasswordEncoder.matches(CharSequence,String) will inco…7.4
- CVE-2025-2223CWE-20: Improper Input Validation vulnerability exists that …8.4
- CVE-2025-22230VMware Tools for Windows contains an authentication bypass v…7.8
- CVE-2025-22231VMware Aria Operations contains a local privilege escalation…7.8
- CVE-2025-22232Spring Cloud Config Server may not use Vault token sent by c…5.3
- CVE-2025-22234The fix applied in CVE-2025-22228 inadvertently broke the ti…5.3
- CVE-2025-22235EndpointRequest.to() creates a matcher for null/** if the ac…7.3
- CVE-2025-22236Minion event bus authorization bypass. An attacker with acce…8.1
- CVE-2025-22237An attacker with access to a minion key can exploit the 'on …6.7
- CVE-2025-22238Directory traversal attack in minion file cache creation. Th…4.2
- CVE-2025-22239Arbitrary event injection on Salt Master. The master's "_min…8.1
Are you affected by CVE-2025-22233?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
