logo

CVE-2021-22113 org.springframework.cloud:spring-cloud-netflix-zuul

Package

Manager: maven
Name: org.springframework.cloud:spring-cloud-netflix-zuul
Vulnerable Version: >=0 <2.2.7

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:U/RC:R

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

EPSS: 0.00165 pctl0.38079

Details

Incorrect Authorization in Spring Cloud Netflix Zuul Applications using the “Sensitive Headers” functionality in Spring Cloud Netflix Zuul 2.2.6.RELEASE and below may be vulnerable to bypassing the “Sensitive Headers” restriction when executing requests with specially constructed URLs. Applications that use Spring Security's StrictHttpFirewall (enabled by default for all URLs) are not affected by the vulnerability, as they reject requests that allow bypassing.

Metadata

Created: 2021-05-10T15:18:50Z
Modified: 2021-05-07T18:52:54Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/05/GHSA-vwpg-f6gw-rjvf/GHSA-vwpg-f6gw-rjvf.json
CWE IDs: ["CWE-863"]
Alternative ID: GHSA-vwpg-f6gw-rjvf
Finding: F006
Auto approve: 1