CVE-2021-22113 describes a security bypass vulnerability in Spring Cloud Netflix Zuul versions 2.2.6.RELEASE and below, specifically impacting applications utilizing its "Sensitive Headers" functionality. An attacker could bypass header restrictions using specially crafted URLs, potentially leading to information disclosure or unauthorized access. This vulnerability is rated Medium severity (CVSS 5.3) with a network attack vector and low complexity, but its impact is limited to integrity and availability, with no confidentiality impact. While no active exploitation, public exploit code, or significant community discussion has been observed, organizations using affected versions should consider mitigation, especially if not employing Spring Security's StrictHttpFirewall.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.2.6CPE matchmatch criteria | cpe:2.3:a:vmware:spring_cloud_netflix_zuul:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.