PT-2022-7238 · Unknown · Spring Cloud Function

Published

2022-06-21

·

Updated

2024-09-07

·

CVE-2022-22979

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Spring Cloud Function versions prior to 3.2.6
Description The issue is related to a caching problem in the Function Catalog component, which can cause a denial-of-service condition when a user directly interacts with the framework's lookup functionality. The vulnerability is also associated with an unlimited allocation of resources, potentially allowing a remote attacker to cause a denial of service through the spring-cloud-function-web module.
Recommendations For versions prior to 3.2.6, update to version 3.2.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the Function Catalog component to minimize the risk of exploitation.

Fix

Allocation of Resources Without Limits

RCE

Weakness Enumeration

Related Identifiers

BDU:2024-00650
BDU:2024-09402
CVE-2022-22979
GHSA-Q588-3544-8G33

Affected Products

Spring Cloud Function