In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote execution on the remote host.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HOracle Commerce Guided Search
APPOracle11.3.2Oracle Communications Cloud Native Core Binding Support Function
APPOracle1.11.022.1.3Oracle Communications Cloud Native Core Console
APPOracle22.2.0Oracle Communications Cloud Native Core Network Exposure Function
APPOracle22.1.0Oracle Communications Cloud Native Core Network Function Cloud Native Environment
APPOracle1.10.0Oracle Communications Cloud Native Core Network Repository Function
APPOracle1.15.01.15.122.1.222.2.0Oracle Communications Cloud Native Core Network Slice Selection Function
APPOracle1.8.022.1.0Oracle Communications Cloud Native Core Security Edge Protection Proxy
APPOracle22.1.1Oracle Communications Cloud Native Core Service Communication Proxy
APPOracle1.15.0VMware Spring Cloud Gateway
APPVmware3.1.0< 3.0.7
CISA KEV — detailsi
- Vendori
- VMware ↗
- Producti
- Spring Cloud Gateway
- Added to KEVi
- May 16, 2022
- Remediation deadline (US Federal)i
- June 6, 2022(overdue)
Apply updates per vendor instructions.
Spring Cloud Gateway applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured.
Related vulnerabilities
RCE w Spring Cloud Function poprzez złośliwy SpEL routing-expression
Spring4Shell — RCE przez data binding w Spring MVC/WebFlux na JDK 9+
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Comm...
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Comm...
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Comm...