CVE-2021-22113 (Medium) detected in spring-cloud-netflix-zuul-2.2.6.RELEASE.jar, spring-cloud-netflix-zuul-2.0.0.RELEASE.jar - autoclosed #76
Labels
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
CVE-2021-22113 - Medium Severity Vulnerability
spring-cloud-netflix-zuul-2.2.6.RELEASE.jar
Spring Cloud Netflix Zuul
Library home page: https://spring.io/spring-cloud/spring-cloud-netflix/spring-cloud-netflix-zuul
Path to dependency file: /dd-java-agent/instrumentation/spring-cloud-zuul-2/spring-cloud-zuul-2.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.springframework.cloud/spring-cloud-netflix-zuul/2.2.6.RELEASE/3e3302c63858df1ea7ac39a5c5989b18f49c9ef2/spring-cloud-netflix-zuul-2.2.6.RELEASE.jar
Dependency Hierarchy:
spring-cloud-netflix-zuul-2.0.0.RELEASE.jar
Spring Cloud Netflix Zuul
Library home page: https://spring.io/spring-cloud
Path to dependency file: /dd-java-agent/instrumentation/spring-cloud-zuul-2/spring-cloud-zuul-2.gradle
Path to vulnerable library: /caches/modules-2/files-2.1/org.springframework.cloud/spring-cloud-netflix-zuul/2.0.0.RELEASE/21d91b6b8aba576971eb0d7e0883981110fe09ed/spring-cloud-netflix-zuul-2.0.0.RELEASE.jar
Dependency Hierarchy:
Found in HEAD commit: 2819174635979a19573ec0ce8e3e2b63a3848079
Found in base branch: master
Applications using the “Sensitive Headers” functionality in Spring Cloud Netflix Zuul 2.2.6.RELEASE and below may be vulnerable to bypassing the “Sensitive Headers” restriction when executing requests with specially constructed URLs. Applications that use Spring Security's StrictHttpFirewall (enabled by default for all URLs) are not affected by the vulnerability, as they reject requests that allow bypassing.
Publish Date: 2021-02-23
URL: CVE-2021-22113
Base Score Metrics:
Type: Upgrade version
Origin: https://tanzu.vmware.com/security/cve-2021-22113
Release Date: 2021-02-23
Fix Resolution (org.springframework.cloud:spring-cloud-netflix-zuul): 2.2.7.RELEASE
Direct dependency fix Resolution (org.springframework.cloud:spring-cloud-starter-netflix-zuul): 2.2.7.RELEASE
⛑️ Automatic Remediation is available for this issue
The text was updated successfully, but these errors were encountered: