CVE-2022-22979

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
21/06/2022
Last modified:
28/06/2022

Description

In Spring Cloud Function versions prior to 3.2.6, it is possible for a user who directly interacts with framework provided lookup functionality to cause a denial-of-service condition due to the caching issue in the Function Catalog component of the framework.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vmware:spring_cloud_function:*:*:*:*:*:*:*:* 3.2.6 (excluding)


References to Advisories, Solutions, and Tools