CVE-2022-22971 ("Spring Framework DoS with STOMP over WebSocket")

back to Advisories

Major news carriers have been reporting on the Spring Framework DoS Vulnerability in Java applications that utilize Spring.

The OME team in Dundee as well as Glencoe Software have evaluated the libraries used by OMERO.server, OMERO.insight as well as the OMERO micro-services. We can say with confidence that OMERO and OMERO Plus are not vulnerable as they do not use STOMP over WebSocket endpoints.

OME and Glencoe will continue to monitor and evaluate the exposure of our various software libraries to these and any other vulnerabilities.

back to top