CVE-2021-22044

Description

In Spring Cloud OpenFeign 3.0.0 to 3.0.4, 2.2.0.RELEASE to 2.2.9.RELEASE, and older unsupported versions, applications using type-level @RequestMappingannotations over Feign client interfaces, can be involuntarily exposing endpoints corresponding to @RequestMapping-annotated interface methods.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
0.328

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2021-22044 are fixed in Spring-cloud-openfeign-core 3.0.5Windows
Vulnerabilities CVE-2021-22044 are fixed in Spring-cloud-openfeign-core 2.2.10Windows
Multiple Vulnerabilities are affected in IBM WebMethods Integration Server 10.15Windows
Multiple Vulnerabilities are affected in IBM WebMethods Integration Server 10.11Windows
Multiple Vulnerabilities are affected in IBM WebMethods Integration Server 11.1Windows
Vulnerabilities CVE-2021-22044 are fixed in Spring-cloud-openfeign-core for Linux 3.0.5Linux
Vulnerabilities CVE-2021-22044 are fixed in Spring-cloud-openfeign-core for Linux 2.2.10Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234