CVE-2022-22946

Source
https://cve.org/CVERecord?id=CVE-2022-22946
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-22946.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-22946
Published
2022-03-04T15:50:06Z
Modified
2026-07-15T01:49:21.648321730Z
Summary
[none]
Details

In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or trusted certificates are set will be configured to use an insecure TrustManager. This makes the gateway able to connect to remote services with invalid or custom certificates.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/22xxx/CVE-2022-22946.json",
    "cna_assigner": "vmware",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "introduced": "Spring cloud gateway versions 3.1.x prior to 3.1.1+"
                },
                {
                    "last_affected": "Spring cloud gateway versions 3.1.x prior to 3.1.1+"
                }
            ]
        }
    ]
}
References

Affected packages

Git / github.com/spring-cloud/spring-cloud-gateway

Affected ranges

Type
GIT
Repo
https://github.com/spring-cloud/spring-cloud-gateway
Events
Database specific
{
    "cpe": "cpe:2.3:a:vmware:spring_cloud_gateway:3.1.0:*:*:*:*:*:*:*",
    "source": "CPE_STRING",
    "extracted_events": [
        {
            "introduced": "3.1.0"
        },
        {
            "last_affected": "3.1.0"
        }
    ]
}

Affected versions

3.*
3.1.0
v3.*
v3.1.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-22946.json"