CVE-2022-22947
CVE-2022-22947
Em resumo
O Spring Cloud Gateway permite que atacantes executem código arbitrário no servidor se o endpoint do Actuator estiver exposto sem proteção. Um pedido maliciosamente elaborado pode permitir a execução remota de comandos.
Detalhe técnico
Vulnerabilidade de injeção de código (CWE-94) no endpoint Actuator do Spring Cloud Gateway permite execução remota de código quando o endpoint está exposto sem autenticação. Pré-condição: Actuator deve estar ativado e acessível publicamente. O vetor de ataque envolve o envio de payloads maliciosos através da interface Actuator, resultando em execução arbitrária de comandos no host.
Resumo gerado e traduzido por IA a partir da descrição oficial.
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote execution on the remote host.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Produtos afetados
n/a · Spring Cloud GatewayPoCs públicas encontradas — 64
githubgithub.com/lucksec/Spring-Cloud-Gateway-CVE-2022-22947★ 223githubgithub.com/whwlsfb/cve-2022-22947-godzilla-memshell★ 211githubgithub.com/SecNN/CVE-2022-22947_Rce_Exp★ 77githubgithub.com/tangxiaofeng7/CVE-2022-22947-Spring-Cloud-Gateway★ 71githubgithub.com/0730Nophone/CVE-2022-22947-★ 60githubgithub.com/crowsec-edtech/CVE-2022-22947★ 38githubgithub.com/0x7eTeam/CVE-2022-22947★ 36githubgithub.com/Zh0um1/CVE-2022-22947★ 28githubgithub.com/Tas9er/SpringCloudGatewayRCE★ 28githubgithub.com/Enokiy/cve-2022-22947-spring-cloud-gateway★ 18githubgithub.com/viemsr/spring_cloud_gateway_memshell★ 18githubgithub.com/B0rn2d/Spring-Cloud-Gateway-Nacos★ 16githubgithub.com/MoCh3n/CVE-2022-22947-Spring-Cloud-Gateway-SpelRCE★ 14githubgithub.com/4nNns/CVE-2022-22947★ 12githubgithub.com/k3rwin/spring-cloud-gateway-rce★ 12githubgithub.com/Wrin9/CVE-2022-22947★ 11githubgithub.com/twseptian/cve-2022-22947★ 11githubgithub.com/Vulnmachines/spring-cve-2022-22947★ 10githubgithub.com/dingxiao77/-cve-2022-22947-★ 9githubgithub.com/SiJiDo/CVE-2022-22947★ 9githubgithub.com/hunzi0/CVE-2022-22947-Rce_POC★ 7githubgithub.com/anansec/CVE-2022-22947_EXP★ 7githubgithub.com/mrknow001/CVE-2022-22947★ 7githubgithub.com/YutuSec/SpEL★ 6githubgithub.com/darkb1rd/cve-2022-22947★ 6githubgithub.com/Greetdawn/CVE-2022-22947★ 5githubgithub.com/Arrnitage/CVE-2022-22947_exp★ 5githubgithub.com/sagaryadav8742/springcloudRCE★ 4githubgithub.com/LY613313/CVE-2022-22947★ 3githubgithub.com/stayfoolish777/CVE-2022-22947-POC★ 3githubgithub.com/nu0l/cve-2022-22947★ 3githubgithub.com/Le1a/CVE-2022-22947★ 2githubgithub.com/22ke/CVE-2022-22947★ 2githubgithub.com/dbgee/CVE-2022-22947★ 2githubgithub.com/Vancomycin-g/CVE-2022-22947★ 2githubgithub.com/kkx600/Burp_VulPscan★ 2githubgithub.com/Wrong-pixel/CVE-2022-22947-exp★ 1githubgithub.com/kmahyyg/CVE-2022-22947★ 1githubgithub.com/Jun-5heng/CVE-2022-22947★ 1githubgithub.com/qq87234770/CVE-2022-22947★ 1githubgithub.com/bysinks/CVE-2022-22947★ 1githubgithub.com/Nathaniel1025/CVE-2022-22947★ 1githubgithub.com/talentsec/Spring-Cloud-Gateway-CVE-2022-22947★ 1githubgithub.com/Sumitpathania03/CVE-2022-22947★ 0githubgithub.com/scopion/cve-2022-22947★ 0githubgithub.com/Summer177/Spring-Cloud-Gateway-CVE-2022-22947★ 0githubgithub.com/BerMalBerIst/CVE-2022-22947★ 0githubgithub.com/flying0er/CVE-2022-22947-goby★ 0githubgithub.com/nanaao/CVE-2022-22947-POC★ 0githubgithub.com/PaoPaoLong-lab/Spring-CVE-2022-22947-★ 0githubgithub.com/hh-hunter/cve-2022-22947-docker★ 0githubgithub.com/scopion/CVE-2022-22947-exp★ 0githubgithub.com/fbion/CVE-2022-22947★ 0githubgithub.com/aesm1p/CVE-2022-22947-POC-Reproduce★ 0githubgithub.com/SanderSchepers1993/CyberSec2026★ 0githubgithub.com/ciri3/spring-cloud-gateway-cve-2022-22947-report★ 0githubgithub.com/entr0pie/demo-cve-2022-22947★ 0githubgithub.com/superneilcn/SpringExploitGUI★ 0githubgithub.com/cc3305/CVE-2022-22947★ 0githubgithub.com/skysliently/CVE-2022-22947-pb-ai★ 0githubgithub.com/shoucheng3/spring-cloud__spring-cloud-gateway_CVE-2022-22947_3-0-6★ 0cve_referencepacketstormsecurity.com/files/168742/Spring-Cloud-Gateway-3.1.0-Remote-Code-Execution.htmlnão verificadocve_referencepacketstormsecurity.com/files/166219/Spring-Cloud-Gateway-3.1.0-Remote-Code-Execution.htmlnão verificadoexploitdbwww.exploit-db.com/exploits/50799não verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://packetstormsecurity.com/files/166219/Spring-Cloud-Gateway-3.1.0-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/168742/Spring-Cloud-Gateway-3.1.0-Remote-Code-Execution.htmlhttps://tanzu.vmware.com/security/cve-2022-22947https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-22947https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.html