Vulnerability: Request Smuggling in Spring Cloud Gateway

Vulnerability: Request Smuggling in Spring Cloud Gateway

CVE-2021-22051 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Applications using Spring Cloud Gateway are vulnerable to specifically crafted requests that could make an extra request on downstream services. Users of affected versions should apply the following mitigation: 3.0.x users should upgrade to 3.0.5+, 2.2.x users should upgrade to 2.2.10.RELEASE or newer.

Learn more about our Cloud Audit.