GHSA-vwpg-f6gw-rjvf
Dashboard / Vulnerabilities / GHSA-vwpg-f6gw-rjvf
Summary: Incorrect Authorization in Spring Cloud Netflix Zuul
Details: Applications using the “Sensitive Headers” functionality in Spring Cloud Netflix Zuul 2.2.6.RELEASE and below may be vulnerable to bypassing the “Sensitive Headers” restriction when executing requests with specially constructed URLs. Applications that use Spring Security's StrictHttpFirewall (enabled by default for all URLs) are not affected by the vulnerability, as they reject requests that allow bypassing.
References: https://nvd.nist.gov/vuln/detail/CVE-2021-22113, https://github.com/spring-cloud/spring-cloud-netflix/commit/8ecb3dca511c3ce0454e42ac31ee2331d7318c07, https://tanzu.vmware.com/security/cve-2021-22113
Affected packages
Package
Name: org.springframework.cloud:spring-cloud-netflix-zuul
Purl: pkg:maven/org.springframework.cloud/spring-cloud-netflix-zuul
Affected ranges
Type: ECOSYSTEM
Events:
