QID 982632
QID 982632: Java (maven) Security Update for org.springframework.cloud:spring-cloud-netflix-zuul (GHSA-vwpg-f6gw-rjvf)
Applications using the Sensitive Headers functionality in Spring Cloud Netflix Zuul 2.2.6.RELEASE and below may be vulnerable to bypassing the Sensitive Headers restriction when executing requests with specially constructed URLs. Applications that use Spring Security's StrictHttpFirewall (enabled by default for all URLs) are not affected by the vulnerability, as they reject requests that allow bypassing.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-vwpg-f6gw-rjvf for updates pertaining to this vulnerability.
Vendor References
- GHSA-vwpg-f6gw-rjvf -
github.com/advisories/GHSA-vwpg-f6gw-rjvf
CVEs related to QID 982632
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-vwpg-f6gw-rjvf | org.springframework.cloud:spring-cloud-netflix-zuul |
|