← back
CVE-2022-22963

CVE-2022-22963

CVSS 9.8 CRITICALEPSS 99.9%● KEVCWE-94
In short

Spring Cloud Function allows attackers to execute arbitrary code on the server by injecting malicious expressions through the routing functionality. This happens because user input is not properly validated before being processed.

Technical detail

A remote attacker can exploit improper input validation in the routing-expression parameter to inject Spring Expression Language (SpEL) payloads, achieving unauthenticated remote code execution. The vulnerability exists in versions 3.1.6, 3.2.2 and older unsupported versions when routing functionality is enabled.

Summary generated and translated by AI from the official description.
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
public PoCs found30
githubgithub.com/hktalent/spring-spel-0day-poc355githubgithub.com/dinosn/CVE-2022-22963116githubgithub.com/darryk10/CVE-2022-2296335githubgithub.com/J0ey17/CVE-2022-22963_Reverse-Shell-Exploit24githubgithub.com/me2nuk/CVE-2022-2296319githubgithub.com/RanDengShiFu/CVE-2022-2296315githubgithub.com/kh4sh3i/Spring-CVE14githubgithub.com/Kirill89/CVE-2022-22963-PoC9githubgithub.com/k3rwin/spring-cloud-function-rce8githubgithub.com/charis3306/CVE-2022-229638githubgithub.com/lemmyz4n3771/CVE-2022-22963-PoC4githubgithub.com/randallbanner/Spring-Cloud-Function-Vulnerability-CVE-2022-22963-RCE4githubgithub.com/iliass-dahman/CVE-2022-22963-POC4githubgithub.com/stevemats/Spring0DayCoreExploit3githubgithub.com/twseptian/cve-2022-229632githubgithub.com/AayushmanThapaMagar/CVE-2022-229631githubgithub.com/SourM1lk/CVE-2022-22963-Exploit1githubgithub.com/puckiestyle/CVE-2022-229631githubgithub.com/SealPaPaPa/SpringCloudFunction-Research1githubgithub.com/Shayz614/CVE-2022-229630githubgithub.com/G01d3nW01f/CVE-2022-229630githubgithub.com/75ACOL/CVE-2022-229630githubgithub.com/Mustafa1986/CVE-2022-229630githubgithub.com/gunzf0x/CVE-2022-229630githubgithub.com/nikn0laty/RCE-in-Spring-Cloud-CVE-2022-229630githubgithub.com/BearClaw96/CVE-2022-22963-Poc-Bearcules0githubgithub.com/jrbH4CK/CVE-2022-229630githubgithub.com/cyberager/CVE-2022-229630exploitdbwww.exploit-db.com/exploits/51577unverifiedcve_referencepacketstormsecurity.com/files/173430/Spring-Cloud-3.2.2-Remote-Command-Execution.htmlunverified
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →