QID 980159
QID 980159: Java (maven) Security Update for org.springframework.cloud:spring-cloud-gateway (GHSA-2r2v-q399-qq93)
Applications using Spring Cloud Gateway are vulnerable to specifically crafted requests that could make an extra request on downstream services. Users of affected versions should apply the following mitigation: 3.0.x users should upgrade to 3.0.5+, 2.2.x users should upgrade to 2.2.10.RELEASE or newer.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-2r2v-q399-qq93 for updates pertaining to this vulnerability.
Vendor References
- GHSA-2r2v-q399-qq93 -
github.com/advisories/GHSA-2r2v-q399-qq93
CVEs related to QID 980159
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-2r2v-q399-qq93 | org.springframework.cloud:spring-cloud-gateway |
|