CyberRota Analysis
AI-GeneratedThe Spring Cloud Gateway JsonToGrpcGatewayFilterFactory is vulnerable to arbitrary resource location access, allowing attackers to define proto descriptors from unauthorized Spring Resource locations. This could lead to unauthorized access or manipulation of gRPC services, posing a significant risk to applications utilizing affected versions of Spring Cloud Gateway. Organizations using versions 3.1.13 and earlier, as well as 4.x and 5.x series, should prioritize patching to mitigate potential exploitation.
Original NVD Description
Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for defining the proto descriptor. Spring Cloud Gateway 5.0.0 - 5.0.2 Spring Cloud Gateway 4.3.0 - 4.3.5 Spring Cloud Gateway 4.0.0 - 4.2.9 Spring Cloud Gateway 3.1.13 and earlier
Related CVEs
Other vulnerabilities affecting the same vendor(s)