VDB
Sign up
CRITICAL10.0

GHSA-3gx9-37ww-9qw6

Spring Cloud Gateway vulnerable to Code Injection when Gateway Actuator endpoint enabled, exposed, unsecured

Quick fix

GHSA-3gx9-37ww-9qw6 — org.springframework.cloud:spring-cloud-gateway: upgrade to the fixed version with the command below.

# pom.xml: bump <version>3.0.7</version> for org.springframework.cloud:spring-cloud-gateway

Details

In Spring Cloud Gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed, and unsecured. A remote attacker could make a maliciously crafted request resulting in arbitrary remote execution on the remote host.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.springframework.cloud:spring-cloud-gateway
Introduced in: 0Fixed in: 3.0.7
Fix# pom.xml: bump <version>3.0.7</version> for org.springframework.cloud:spring-cloud-gateway
Maven/org.springframework.cloud:spring-cloud-gateway
Introduced in: 3.1.0Fixed in: 3.1.1
Fix# pom.xml: bump <version>3.1.1</version> for org.springframework.cloud:spring-cloud-gateway

References