SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-22946

In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or trusted certificates are set will be configured to use an insecure TrustManager.

MEDIUM 5.5EPSS 4.85%

Does this matter?

Lower severity and a low EPSS score (4.85%). Track it; it rarely justifies an emergency change on its own.

Description

In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or trusted certificates are set will be configured to use an insecure TrustManager. This makes the gateway able to connect to remote services with invalid or custom certificates.

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS
4.85% probability · 92th percentile
CISA KEV
Not listed
Weakness
CWE-295
Affected
vmware/spring cloud gateway · oracle/commerce guided search · oracle/communications cloud native core binding support function · oracle/communications cloud native core console · oracle/communications cloud native core network repository function · oracle/communications cloud native core security edge protection proxy
Source
security@vmware.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.