VulnerabilityModified
CVE-2022-22946
In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or trusted certificates are set will be configured to use an insecure TrustManager.
MEDIUM 5.5EPSS 4.85%
Does this matter?
Lower severity and a low EPSS score (4.85%). Track it; it rarely justifies an emergency change on its own.
Description
In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or trusted certificates are set will be configured to use an insecure TrustManager. This makes the gateway able to connect to remote services with invalid or custom certificates.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 4.85% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-295
- Affected
- vmware/spring cloud gateway · oracle/commerce guided search · oracle/communications cloud native core binding support function · oracle/communications cloud native core console · oracle/communications cloud native core network repository function · oracle/communications cloud native core security edge protection proxy
- Source
- security@vmware.com
References
- https://tanzu.vmware.com/security/cve-2022-22946Vendor Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlPatch, Third Party Advisory
- https://tanzu.vmware.com/security/cve-2022-22946Vendor Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlPatch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.