GHSA-pf94-6v2v-cm3j
HIGHCVE-2021-22044In Spring Cloud OpenFeign 3.0.0 to 3.0.4, 2.2.0.RELEASE to 2.2.9.RELEASE, and older unsupported versions, applications using type-level @RequestMappingannotations over Feign client interfaces, can be involuntarily exposing endpoints corresponding to @RequestMapping-annotated interface methods.
- Affected
- >= 2.2.0, <= 2.2.9, >= 3.0.0, <= 3.0.4
- Fixed in
- 2.2.10
- Weakness
- CWE-668
- Published
- 2022-05-24
- Source
- github