Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2r2v-q399-qq93

Опубликовано: 10 нояб. 2021
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Request injection in Spring Cloud Gateway

Applications using Spring Cloud Gateway are vulnerable to specifically crafted requests that could make an extra request on downstream services. Users of affected versions should apply the following mitigation: 3.0.x users should upgrade to 3.0.5+, 2.2.x users should upgrade to 2.2.10.RELEASE or newer.

Пакеты

Наименование

org.springframework.cloud:spring-cloud-gateway

maven
Затронутые версииВерсия исправления

>= 3.0.0, < 3.0.5

3.0.5

Наименование

org.springframework.cloud:spring-cloud-gateway

maven
Затронутые версииВерсия исправления

>= 2.2.0, <= 2.2.10.RELEASE

2.2.10.RELEASE0.5

EPSS

Процентиль: 34%
0.00135
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-352
CWE-863

Связанные уязвимости

CVSS3: 6.5
nvd
около 4 лет назад

Applications using Spring Cloud Gateway are vulnerable to specifically crafted requests that could make an extra request on downstream services. Users of affected versions should apply the following mitigation: 3.0.x users should upgrade to 3.0.5+, 2.2.x users should upgrade to 2.2.10.RELEASE or newer.

EPSS

Процентиль: 34%
0.00135
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-352
CWE-863