Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2022-22963

In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.945
EPSS Ranking 100.0%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Proposed Action
When using routing functionality in VMware Tanzu's Spring Cloud Function, it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
Ransomware Campaign
Unknown
References
Products affected by CVE-2022-22963


Contact Us

Shodan ® - All rights reserved