CVE Database
/

CVE-2021-22051

Back to search

CVE-2021-22051

Published: Nov 8, 2021

Modified: Aug 3, 2024

PUBLISHED

Description

Applications using Spring Cloud Gateway are vulnerable to specifically crafted requests that could make an extra request on downstream services. Users of affected versions should apply the following mitigation: 3.0.x users should upgrade to 3.0.5+, 2.2.x users should upgrade to 2.2.10.RELEASE or newer.

VendorProductVersions

n/a

Spring Cloud Gateway

affected
3.0.0 to 3.0.4, 2.2.0.RELEASE to 2.2.9.RELEASE, and older versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now