Sploitus

CVE-2022-22946

No indexed exploits for CVE-2022-22946 yet

In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or trusted certificates are set will be configured to use an insecure TrustManager. This makes the gateway able to connect to remote services with invalid or custom certificates.

Affected products
Spring Cloud Gateway
Vmware Spring Cloud Gateway
= 3.1.0
Fix
Available
CVSS 3.1
5.5 MEDIUM
EPSS
4.8% (91th percentile)
Weakness
CWE-295
NVD status
Modified
Published
2022-03-04
CVE-2022-22946 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2022-22946 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2022-22946 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.