CVE-2021-22113 – org.springframework.cloud:spring-cloud-netflix-zuul
Package
Manager: maven
Name: org.springframework.cloud:spring-cloud-netflix-zuul
Vulnerable Version: >=0 <2.2.7
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:U/RC:R
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00165 pctl0.38079
Details
Incorrect Authorization in Spring Cloud Netflix Zuul Applications using the “Sensitive Headers” functionality in Spring Cloud Netflix Zuul 2.2.6.RELEASE and below may be vulnerable to bypassing the “Sensitive Headers” restriction when executing requests with specially constructed URLs. Applications that use Spring Security's StrictHttpFirewall (enabled by default for all URLs) are not affected by the vulnerability, as they reject requests that allow bypassing.
Metadata
Created: 2021-05-10T15:18:50Z
Modified: 2021-05-07T18:52:54Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/05/GHSA-vwpg-f6gw-rjvf/GHSA-vwpg-f6gw-rjvf.json
CWE IDs: ["CWE-863"]
Alternative ID: GHSA-vwpg-f6gw-rjvf
Finding: F006
Auto approve: 1