ZeroHour

CVE-2022-22946

CVSS 3.1
5.5 medium
EPSS
5%p91
Published
()
Modified
Description

In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or trusted certificates are set will be configured to use an insecure TrustManager. This makes the gateway able to connect to remote services with invalid or custom certificates.

Vendors
vmwareoracle
Products
spring cloud gateway, commerce guided search, communications cloud native core binding support function, communications cloud native core console, communications cloud native core network repository function, communications cloud native core security edge protection proxy
Weakness
CWE-295
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.