VMware Spring Cloud Gateway 3.1.0

CPE Details

VMware Spring Cloud Gateway 3.1.0
3.1.0
2023-01-11
18h28 +00:00
2023-03-03
15h57 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:vmware:spring_cloud_gateway:3.1.0:-:*:*:*:*:*:*

Informations

Vendor

vmware

Product

spring_cloud_gateway

Version

3.1.0

Update

-

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2022-22946 2022-03-04
14h50 +00:00
In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or trusted certificates are set will be configured to use an insecure TrustManager. This makes the gateway able to connect to remote services with invalid or custom certificates.
5.5
Medium
CVE-2022-22947 2022-03-03
00h00 +00:00
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote execution on the remote host.
10
Critical