AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2022-22946

MEDIUM · CVSS 5.5 EPSS 4.85%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2022-03-04 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 5.5. It may be remotely exploitable.

CVE
CVE-2022-22946
Severity
MEDIUM
CVSS
5.5
EPSS
4.85%

Original NVD Description

In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or trusted certificates are set will be configured to use an insecure TrustManager. This makes the gateway able to connect to remote services with invalid or custom certificates.

Related CVEs

Other vulnerabilities affecting the same vendor(s)