CVE-2022-22946: Medium severity spring cloud gateway vulnerability
In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or trusted certificates are set will be configured to use an insecure TrustManager. This makes the gateway able to connect to remote services with invalid or custom certificates.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-22946?
CVE-2022-22946 is a vulnerability in spring cloud gateway versions prior to 3.1.1+ that allows the gateway to connect to remote services with invalid or custom certificates.
How does CVE-2022-22946 impact applications?
CVE-2022-22946 affects applications that are configured to enable HTTP2 without setting a key store or trusted certificates, making them vulnerable to insecure TrustManager.
Which software versions are affected by CVE-2022-22946?
CVE-2022-22946 affects the following software versions: VMware Spring Cloud Gateway 3.1.0, Oracle Commerce Guided Search 11.3.2, Oracle Communications Cloud Native Core Binding Support Function 22.1.3, Oracle Communications Cloud Native Core Console 22.2.0, Oracle Communications Cloud Native Core Network Repository Function 22.1.2 and 22.2.0, VMware Spring Cloud Gateway 22.1.1.
What is the severity of CVE-2022-22946?
CVE-2022-22946 has a severity rating of medium, with a severity value of 5.5.
Where can I find more information about CVE-2022-22946?
You can find more information about CVE-2022-22946 at the following references: [VMware Security Advisory](https://tanzu.vmware.com/security/cve-2022-22946) and [Oracle Security Alerts](https://www.oracle.com/security-alerts/cpujul2022.html).