CVE-2021-22051: Medium severity spring cloud gateway vulnerability
Applications using Spring Cloud Gateway are vulnerable to specifically crafted requests that could make an extra request on downstream services. Users of affected versions should apply the following mitigation: 3.0.x users should upgrade to 3.0.5+, 2.2.x users should upgrade to 2.2.10.RELEASE or newer.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-22051?
CVE-2021-22051 is a vulnerability in Applications using Spring Cloud Gateway that allows for specifically crafted requests to make an extra request on downstream services.
What is the severity of CVE-2021-22051?
CVE-2021-22051 has a severity rating of 6.5, which is considered medium.
Which versions of Spring Cloud Gateway are affected by CVE-2021-22051?
Versions up to and including 2.2.10.RELEASE and versions between 3.0.0 and 3.0.5 of Spring Cloud Gateway are affected by CVE-2021-22051.
How can I mitigate the vulnerability?
To mitigate CVE-2021-22051, users of Spring Cloud Gateway should upgrade to version 3.0.5+ if using 3.0.x, and upgrade to version 2.2.10.RELEASE or newer if using 2.2.x.
Where can I find more information about CVE-2021-22051?
More information about CVE-2021-22051 can be found at the following reference: https://tanzu.vmware.com/security/cve-2021-22051