Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vwpg-f6gw-rjvf

Опубликовано: 10 мая 2021
Источник: github
Github: Прошло ревью

Описание

Incorrect Authorization in Spring Cloud Netflix Zuul

Applications using the “Sensitive Headers” functionality in Spring Cloud Netflix Zuul 2.2.6.RELEASE and below may be vulnerable to bypassing the “Sensitive Headers” restriction when executing requests with specially constructed URLs. Applications that use Spring Security's StrictHttpFirewall (enabled by default for all URLs) are not affected by the vulnerability, as they reject requests that allow bypassing.

Пакеты

Наименование

org.springframework.cloud:spring-cloud-netflix-zuul

maven
Затронутые версииВерсия исправления

< 2.2.7

2.2.7

EPSS

Процентиль: 38%
0.00165
Низкий

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 5.3
nvd
почти 5 лет назад

Applications using the “Sensitive Headers” functionality in Spring Cloud Netflix Zuul 2.2.6.RELEASE and below may be vulnerable to bypassing the “Sensitive Headers” restriction when executing requests with specially constructed URLs. Applications that use Spring Security's StrictHttpFirewall (enabled by default for all URLs) are not affected by the vulnerability, as they reject requests that allow bypassing.

EPSS

Процентиль: 38%
0.00165
Низкий

Дефекты

CWE-863