Description
In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or trusted certificates are set will be configured to use an insecure TrustManager. This makes the gateway able to connect to remote services with invalid or custom certificates.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-28071 | In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or trusted certificates are set will be configured to use an insecure TrustManager. This makes the gateway able to connect to remote services with invalid or custom certificates. |
References
History
No history.
Subscriptions
Oracle
Subscribe
Commerce Guided Search
Subscribe
Communications Cloud Native Core Binding Support Function
Subscribe
Communications Cloud Native Core Console
Subscribe
Communications Cloud Native Core Network Repository Function
Subscribe
Communications Cloud Native Core Security Edge Protection Proxy
Subscribe
Vmware
Subscribe
Spring Cloud Gateway
Subscribe
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2024-08-03T03:28:42.597Z
Reserved: 2022-01-10T00:00:00.000Z
Link: CVE-2022-22946
No data.
Status : Modified
Published: 2022-03-04T16:15:10.377
Modified: 2024-11-21T06:47:39.557
Link: CVE-2022-22946
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD