Filtered by vendor Vmware Subscriptions
Filtered by product Spring Cloud Netflix Zuul Subscriptions
Total 1 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2021-22113 1 Vmware 1 Spring Cloud Netflix Zuul 2021-03-02 5.3 Medium
Applications using the “Sensitive Headers” functionality in Spring Cloud Netflix Zuul 2.2.6.RELEASE and below may be vulnerable to bypassing the “Sensitive Headers” restriction when executing requests with specially constructed URLs. Applications that use Spring Security's StrictHttpFirewall (enabled by default for all URLs) are not affected by the vulnerability, as they reject requests that allow bypassing.