VRT 391,810 CVEs tracked · 15,472 in RASP scope · data as of 44 minutes ago
Reset
More filters (2)
Columns
Vendor org.springframework.cloudProduct spring-cloud-netflix
Overview 3 matches, all in RASP scope · 0 protected · 0 KEV · 2 public PoC · 0 CISA SSVC · 0 EPSS ≥ 0.5 · 0 disputed
3matches, all in RASP scope 0protected0.0% 0KEV0.0% 2public PoC66.7% 0CISA SSVC0.0% 0EPSS ≥ 0.50.0% 0disputed0.0%
Critical 0 0.0% High 1 33.3% Medium 2 66.7% Low 0 0.0% None 0 0.0% Unknown 0 0.0%
Protected by RASP 0 0.0% Rule in development 0 0.0% Mitigation candidate 2 66.7% No exploit published 1 33.3% No fix identified 0 0.0% Mitigated by environment configuration 0 0.0% Queued for review 0 0.0% Not applicable 0 0.0% Out of RASP scope 0 0.0% Rejected 0 0.0%
blocked by ARMR today 0 0.0% not blocked 3 100.0% not established 0 0.0% unrecorded 0 0.0%
Exploited in the wild 0 0.0% Working exploit published 2 66.7% Proof of concept only 0 0.0% Forecast only 0 0.0% No public exploit 1 33.3%
split by peak 1 / month
Unknown: 0None: 0Low: 0Medium: 2High: 1Critical: 0 Rejected: 0Out of RASP scope: 0Not applicable: 0Queued for review: 0Mitigated by environment configuration: 0No fix identified: 0No exploit published: 1Mitigation candidate: 2Rule in development: 0Protected by RASP: 0 unrecorded: 0not established: 0not blocked: 3blocked by ARMR today: 0 No public exploit: 1Forecast only: 0Proof of concept only: 0Working exploit published: 2Exploited in the wild: 0 August 2020: 1 CVE September 2020: 0 CVEs October 2020: 0 CVEs November 2020: 0 CVEs December 2020: 0 CVEs January 2021: 0 CVEs February 2021: 1 CVE March 2021: 0 CVEs April 2021: 0 CVEs May 2021: 0 CVEs June 2021: 0 CVEs July 2021: 0 CVEs August 2021: 0 CVEs September 2021: 0 CVEs October 2021: 0 CVEs November 2021: 1 CVE
Sep 20Nov 20Jan 21Mar 21May 21Jul 21Sep 21Nov 21
3 matches CSV JSON
CVE Severity Published Status Exploitation Description
CVE-2021-22053 High 2021-11-19 Mitigation candidate Working exploit published Applications using both `spring-cloud-netflix-hystrix-dashboard` and `spring-boot-starter-thymeleaf` expose a way to execute code submitted within the request URI path during the resolution of view templates. When a request is made at `/hystrix/monitor;[user-provided data]`, the path elements following `hystrix/monitor` are being evaluated as SpringEL expressions, which can lead to code execution.
CVE-2021-22113 Medium 2021-02-23 No exploit published No public exploit Applications using the “Sensitive Headers” functionality in Spring Cloud Netflix Zuul 2.2.6.RELEASE and below may be vulnerable to bypassing the “Sensitive Headers” restriction when executing requests with specially constructed URLs. Applications that use Spring Security's StrictHttpFirewall (enabled by default for all URLs) are not affected by the vulnerability, as they reject requests that allow bypassing.
CVE-2020-5412 Medium 2020-08-07 Mitigation candidate Working exploit published Spring Cloud Netflix, versions 2.2.x prior to 2.2.4, versions 2.1.x prior to 2.1.6, and older unsupported versions allow applications to use the Hystrix Dashboard proxy.stream endpoint to make requests to any server reachable by the server hosting the dashboard. A malicious user, or attacker, can send a request to other servers that should not be exposed publicly.