PT-2021-14845 · Spring · Spring Cloud Openfeign

Published

2021-10-28

·

Updated

2022-10-25

·

CVE-2021-22044

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Spring Cloud OpenFeign versions 2.2.0.RELEASE through 2.2.9.RELEASE Spring Cloud OpenFeign versions 3.0.0 through 3.0.4
Description The issue affects applications using type-level @RequestMapping annotations over Feign client interfaces, potentially exposing endpoints corresponding to @RequestMapping-annotated interface methods.
Recommendations For Spring Cloud OpenFeign versions 2.2.0.RELEASE through 2.2.9.RELEASE, consider updating to a version outside of this range to mitigate the risk. For Spring Cloud OpenFeign versions 3.0.0 through 3.0.4, consider updating to a version outside of this range to mitigate the risk. As a temporary workaround, consider restricting the use of type-level @RequestMapping annotations over Feign client interfaces until a patch is available.

Fix

Information Disclosure

Exposure of Resource to Wrong Sphere

Weakness Enumeration

Related Identifiers

CVE-2021-22044
GHSA-PF94-6V2V-CM3J

Affected Products

Spring Cloud Openfeign