Description
In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or trusted certificates are set will be configured to use an insecure TrustManager. This makes the gateway able to connect to remote services with invalid or custom certificates.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Spell Check Cross-Site Request Forgery (7.1.9)
WordPress Plugin Import any XML or CSV File to WordPress Multiple Vulnerabilities (3.2.4)
WordPress Ultimate Member Plugin CVE-2020-36157 Vulnerability (CVE-2020-36157)
ProjectSend Use of Insufficiently Random Values Vulnerability (CVE-2024-7659)
WordPress Plugin Forym-Modern Discussion Forum for Wordpress-Forums Cross-Site Scripting (1.5.8)