VMware Spring Cloud Gateway
cpe:2.3:a:vmware:spring_cloud_gateway:*:*:*:*:*:*:*
- 3.1.0
A vulnerability exists in Spring Cloud Gateway versions prior to 3.1.1+ that allows applications enabled for HTTP2, without a key store or trusted certificates, to use an insecure TrustManager. This misconfiguration enables the gateway to connect to remote services using invalid or custom certificates.
Exploitation of this vulnerability allows for connections to remote services with invalid or custom certificates, potentially leading to man-in-the-middle attacks or other security risks associated with untrusted certificates.
Users of Spring Cloud Gateway 3.1.0 should upgrade to version 3.1.1 or later. No additional steps are necessary.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.