In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/173430/Spring-Cloud-3.2.2-Remote-Command-Execution.html | Exploit Third Party Advisory VDB Entry |
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0005 | Third Party Advisory |
https://tanzu.vmware.com/security/cve-2022-22963 | Vendor Advisory |
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-java-spring-scf-rce-DQrHhJxH | Third Party Advisory |
https://www.oracle.com/security-alerts/cpuapr2022.html | Patch Third Party Advisory |
https://www.oracle.com/security-alerts/cpujul2022.html | Patch Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
28 Jun 2024, 14:08
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.com/files/173430/Spring-Cloud-3.2.2-Remote-Command-Execution.html - Exploit, Third Party Advisory, VDB Entry |
13 Jul 2023, 23:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
13 Jul 2023, 17:11
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-917 |
Information
Published : 2022-04-01 23:15
Updated : 2024-06-28 14:08
NVD link : CVE-2022-22963
Mitre link : CVE-2022-22963
CVE.ORG link : CVE-2022-22963
JSON object : View
Products Affected
oracle
- financial_services_analytical_applications_infrastructure
- communications_cloud_native_core_security_edge_protection_proxy
- communications_cloud_native_core_unified_data_repository
- banking_supply_chain_finance
- banking_credit_facilities_process_management
- financial_services_enterprise_case_management
- communications_cloud_native_core_policy
- communications_cloud_native_core_console
- sd-wan_edge
- communications_cloud_native_core_network_slice_selection_function
- communications_cloud_native_core_network_exposure_function
- banking_trade_finance_process_management
- banking_corporate_lending_process_management
- financial_services_behavior_detection_platform
- banking_virtual_account_management
- communications_cloud_native_core_network_repository_function
- banking_branch
- communications_cloud_native_core_network_function_cloud_native_environment
- product_lifecycle_analytics
- banking_cash_management
- communications_communications_policy_management
- banking_origination
- communications_cloud_native_core_automated_test_suite
- banking_electronic_data_exchange_for_corporates
- mysql_enterprise_monitor
- banking_liquidity_management
- retail_xstore_point_of_service
vmware
- spring_cloud_function