« Back to list

CVE-2025-22228

Status: DeferredHigh (7.4)—

BCryptPasswordEncoder.matches(CharSequence,String) will incorrectly return true for passwords larger than 72 characters as long as the first 72 characters are the same.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

🎯 ATT&CK techniques

How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.

Spring Security BCrypt acepta contraseñas >72 caracteres truncadas; atacante remoto explota esta validación débil (CWE-287) para autenticarse con credenciales incompletas (AV:N, PR:N).

Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.

🛡️ ATT&CK mitigations that cover these techniques

Affected technologies (1)

⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2025-22228",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-22228",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-03-21T03:55:17.357088Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@vmware.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.4,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 2.2
      }
    ]
  },
  "affected": [
    {
      "source": "security@vmware.com",
      "affectedData": [
        {
          "vendor": "Spring",
          "product": "Spring Security",
          "versions": [
            {
              "status": "affected",
              "version": "5.7.x",
              "lessThan": "5.7.16",
              "versionType": "Enterprise Support Only"
            },
            {
              "status": "affected",
              "version": "5.8.x",
              "lessThan": "5.8.18",
              "versionType": "Enterprise Support Only"
            },
            {
              "status": "affected",
              "version": "6.0.x",
              "lessThan": "6.0.16",
              "versionType": "Enterprise Support Only"
            },
            {
              "status": "affected",
              "version": "6.1.x",
              "lessThan": "6.1.14",
              "versionType": "Enterprise Support Only"
            },
            {
              "status": "affected",
              "version": "6.2.x",
              "lessThan": "6.2.10",
              "versionType": "Enterprise Support Only"
            },
            {
              "status": "affected",
              "version": "6.3.x",
              "lessThan": "6.3.8",
              "versionType": "OSS"
            },
            {
              "status": "affected",
              "version": "6.4.x",
              "lessThan": "6.4.4",
              "versionType": "OSS"
            }
          ],
          "packageName": "Spring Security",
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-03-20T06:15:23.087",
  "references": [
    {
      "url": "https://spring.io/security/cve-2025-22228",
      "source": "security@vmware.com"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20250425-0009/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "BCryptPasswordEncoder.matches(CharSequence,String) will incorrectly return true for passwords larger than 72 characters as long as the first 72 characters are the same."
    },
    {
      "lang": "es",
      "value": "BCryptPasswordEncoder.matches(CharSequence,String) devolverá incorrectamente verdadero para contraseñas con más de 72 caracteres siempre que los primeros 72 caracteres sean iguales."
    }
  ],
  "lastModified": "2026-06-17T08:45:45.500",
  "sourceIdentifier": "security@vmware.com"
}