PT-2022-7238 · Unknown · Spring Cloud Function

CVE-2022-22979

·

Published

2022-06-21

·

Updated

2024-09-07

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:N/C:C/I:P/A:N
Name of the Vulnerable Software and Affected Versions Spring Cloud Function versions prior to 3.2.6
Description The issue is related to a caching problem in the Function Catalog component, which can cause a denial-of-service condition when a user directly interacts with the framework's lookup functionality. The vulnerability is also associated with an unlimited allocation of resources, potentially allowing a remote attacker to cause a denial of service through the spring-cloud-function-web module.
Recommendations For versions prior to 3.2.6, update to version 3.2.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the Function Catalog component to minimize the risk of exploitation.

Exploit

Fix

Allocation of Resources Without Limits

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-00650
BDU:2024-09402
CVE-2022-22979
GHSA-Q588-3544-8G33

Affected Products

Spring Cloud Function