PT-2022-7238 · Unknown · Spring Cloud Function
Published
2022-06-21
·
Updated
2024-09-07
·
CVE-2022-22979
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Spring Cloud Function versions prior to 3.2.6
Description
The issue is related to a caching problem in the Function Catalog component, which can cause a denial-of-service condition when a user directly interacts with the framework's lookup functionality. The vulnerability is also associated with an unlimited allocation of resources, potentially allowing a remote attacker to cause a denial of service through the spring-cloud-function-web module.
Recommendations
For versions prior to 3.2.6, update to version 3.2.6 or later to resolve the issue.
As a temporary workaround, consider restricting access to the Function Catalog component to minimize the risk of exploitation.
Fix
Allocation of Resources Without Limits
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Spring Cloud Function