Описание
Applications using the “Sensitive Headers” functionality in Spring Cloud Netflix Zuul 2.2.6.RELEASE and below may be vulnerable to bypassing the “Sensitive Headers” restriction when executing requests with specially constructed URLs. Applications that use Spring Security's StrictHttpFirewall (enabled by default for all URLs) are not affected by the vulnerability, as they reject requests that allow bypassing.
Ссылки
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.2.6 (включая)
cpe:2.3:a:vmware:spring_cloud_netflix_zuul:*:*:*:*:*:*:*:*
EPSS
Процентиль: 38%
0.00165
Низкий
5.3 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-863
Связанные уязвимости
EPSS
Процентиль: 38%
0.00165
Низкий
5.3 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-863