First published: Tue Jun 21 2022(Updated: )
In Spring Cloud Function versions prior to 3.2.6, it is possible for a user who directly interacts with framework provided lookup functionality to cause a denial-of-service condition due to the caching issue in the Function Catalog component of the framework.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
Vmware Spring Cloud Function | <3.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-22979 is a vulnerability in Spring Cloud Function versions prior to 3.2.6 that allows a user to cause a denial-of-service condition due to a caching issue in the Function Catalog component of the framework.
The severity of CVE-2022-22979 is high with a CVSS score of 7.5.
CVE-2022-22979 affects VMware Spring Cloud Function versions prior to 3.2.6.
To fix CVE-2022-22979, it is recommended to upgrade to Spring Cloud Function version 3.2.6 or newer.
More information about CVE-2022-22979 can be found at: [https://tanzu.vmware.com/security/cve-2022-22979](https://tanzu.vmware.com/security/cve-2022-22979)