imPC@ndo IT

Tracker / CVE-2022-22946

CVE-2022-22946

Medium 5.5

In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or trusted certificates are set will be configured to use an insecure TrustManager. This makes the gateway able to connect to remote services with invalid or custom certificates.

Affected products and versions

oracle commerce_guided_search
oracle communications_cloud_native_core_binding_support_function
oracle communications_cloud_native_core_console
oracle communications_cloud_native_core_network_repository_function
oracle communications_cloud_native_core_security_edge_protection_proxy
vmware spring_cloud_gateway

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References