In spring cloud gateway versions prior to 3.1.1+ ,...
Moderate severity
Unreviewed
Published
Mar 5, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Mar 4, 2022
Published to the GitHub Advisory Database
Mar 5, 2022
Last updated
Jan 27, 2023
In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or trusted certificates are set will be configured to use an insecure TrustManager. This makes the gateway able to connect to remote services with invalid or custom certificates.
References