PT-2021-14847 · Spring · Spring Cloud Gateway

Frederico Biehl

+1

·

Published

2021-11-08

·

Updated

2021-11-10

·

CVE-2021-22051

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Spring Cloud Gateway versions 3.0.0 through 3.0.4 Spring Cloud Gateway versions 2.2.0 through 2.2.9
Description Applications using Spring Cloud Gateway are vulnerable to specifically crafted requests that could make an extra request on downstream services.
Recommendations For Spring Cloud Gateway version 3.0.x, upgrade to 3.0.5 or newer. For Spring Cloud Gateway version 2.2.x, upgrade to 2.2.10.RELEASE or newer.

Fix

Incorrect Authorization

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-22051
GHSA-2R2V-Q399-QQ93

Affected Products

Spring Cloud Gateway