Beveiligingsadvies

CVE-2022-22946

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2022-03-04 15:50:06
Laatst bijgewerkt 2024-08-03 03:28:42
Toegewezen door vmware
CVSS-score geen score
Status PUBLISHED

Beschrijving

In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or trusted certificates are set will be configured to use an insecure TrustManager. This makes the gateway able to connect to remote services with invalid or custom certificates.