CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.5. It may be remotely exploitable.
CVE
CVE-2022-22946
Severity
MEDIUM
CVSS
5.5
EPSS
4.85%
Original NVD Description
In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or trusted certificates are set will be configured to use an insecure TrustManager. This makes the gateway able to connect to remote services with invalid or custom certificates.
Related CVEs
Other vulnerabilities affecting the same vendor(s)