CVE-2022-22946

5.5MEDIUM

Key Information:

Vendor
Vmware
Vendor
CVE Published:
4 March 2022

Summary

In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or trusted certificates are set will be configured to use an insecure TrustManager. This makes the gateway able to connect to remote services with invalid or custom certificates.

Affected Version(s)

Spring Cloud Gateway Spring cloud gateway versions 3.1.x prior to 3.1.1+

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.