Insecure TrustManager in Spring Cloud Gateway Across Versions
CVE-2022-22946

5.5MEDIUM

Key Information:

Vendor
Vmware
Vendor
CVE Published:
4 March 2022

Summary

Spring Cloud Gateway versions prior to 3.1.1+ are susceptible to a vulnerability where applications configured to enable HTTP2 without a key store or trusted certificates utilize an insecure TrustManager. This misconfiguration allows the gateway to establish connections with remote services that present invalid or custom certificates, potentially exposing systems to security risks.

Affected Version(s)

Spring Cloud Gateway Spring cloud gateway versions 3.1.x prior to 3.1.1+

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.