PT-2021-14855 · Spring · Spring Cloud Netflix Zuul
Threedr3Am
·
Published
2021-02-23
·
Updated
2021-05-10
·
CVE-2021-22113
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Spring Cloud Netflix Zuul versions 2.2.6.RELEASE and below
Description
The issue allows bypassing the "Sensitive Headers" restriction when executing requests with specially constructed URLs. Applications using Spring Security's StrictHttpFirewall are not affected, as they reject requests that allow bypassing.
Recommendations
For Spring Cloud Netflix Zuul versions 2.2.6.RELEASE and below, consider disabling the "Sensitive Headers" functionality until a patch is available. As a temporary workaround, enable Spring Security's StrictHttpFirewall to reject requests that allow bypassing the "Sensitive Headers" restriction. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Spring Cloud Netflix Zuul