Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Vmware Subscribe
Filtered by product Spring Cloud Netflix Zuul
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-22113 1 Vmware 1 Spring Cloud Netflix Zuul 2021-03-02 4.3 MEDIUM 5.3 MEDIUM
Applications using the “Sensitive Headers” functionality in Spring Cloud Netflix Zuul 2.2.6.RELEASE and below may be vulnerable to bypassing the “Sensitive Headers” restriction when executing requests with specially constructed URLs. Applications that use Spring Security's StrictHttpFirewall (enabled by default for all URLs) are not affected by the vulnerability, as they reject requests that allow bypassing.