Description
In Spring Cloud Function versions prior to 3.2.6, it is possible for a user who directly interacts with framework provided lookup functionality to cause a denial-of-service condition due to the caching issue in the Function Catalog component of the framework.
Remediation
References
https://tanzu.vmware.com/security/cve-2022-22979
Related Vulnerabilities
CVE-2022-36881 Vulnerability in maven package org.jenkins-ci.plugins:git-client
CVE-2018-5382 Vulnerability in maven package org.bouncycastle:bcprov-jdk14
CVE-2023-26049 Vulnerability in maven package org.eclipse.jetty:jetty-http
CVE-2019-12421 Vulnerability in maven package org.apache.nifi:nifi-web-api
CVE-2022-31166 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore