KEVIntel
10.0
CVSS
Critical

CVE-2022-22947

PUBLISHED

In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator...

Exploited in the wild Remote Low complexity No user interaction
Vendor
VMware
Product
Spring Cloud Gateway
Published
Mar 03, 2022
EPSS

Description

In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote execution on the remote host.

java cisa nuclei_scanner metasploit

CVSS scores

CVSS v3.1 10.0 Critical

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CVSS v2.0 6.8

AV:N/AC:M/Au:N/C:P/I:P/A:P

Exploitation status

Exploited in the wild

Recorded 2022-05-16 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
Yes
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA May 16, 2022

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

spring_cloud_gateway_rce

metasploit · Created Unknown

Metasploit module for CVE-2022-22947

Le1a/CVE-2022-22947

github · Created 2023-05-26 11:52:22 UTC · 2 stars

Spring Cloud Gateway Actuator API SpEL表达式注入命令执行Exp

Zh0um1/CVE-2022-22947

github · Created 2023-02-07 01:59:01 UTC · 26 stars

CVE-2022-22947注入哥斯拉内存马

SiJiDo/CVE-2022-22947

github · Created 2022-08-23 06:38:46 UTC · 8 stars

LY613313/CVE-2022-22947

github · Created 2022-08-03 02:51:26 UTC · 3 stars

stayfoolish777/CVE-2022-22947-POC

github · Created 2022-06-08 09:52:23 UTC · 2 stars

批量检测Spring Cloud Gateway 远程代码执行漏洞 Spring_Cloud_Gateway_RCE_POC-CVE-2022-22947

anansec/CVE-2022-22947_EXP

github · Created 2022-05-19 14:58:45 UTC · 5 stars

一个可单独、批量验证的脚本,也可以反弹shell

0730Nophone/CVE-2022-22947-

github · Created 2022-05-16 15:27:41 UTC · 53 stars

Spring Cloud Gateway Actuator API SpEL表达式注入命令执行(CVE-2022-22947) 注入哥斯拉内存马

4nNns/CVE-2022-22947

github · Created 2022-04-06 09:40:05 UTC · 12 stars

Spring-Cloud-Spel-RCE

Nathaniel1025/CVE-2022-22947

github · Created 2022-03-25 12:43:53 UTC · 1 stars

poc for CVE-2022-22947

Wrin9/CVE-2022-22947

github · Created 2022-03-17 09:12:51 UTC · 13 stars

CVE-2022-22947_POC_EXP

Arrnitage/CVE-2022-22947_exp

github · Created 2022-03-10 03:51:47 UTC · 6 stars

CVE-2022-22947 Exploit script

0x7eTeam/CVE-2022-22947

github · Created 2022-03-08 09:32:36 UTC · 35 stars

CVE-2022-22947_EXP,CVE-2022-22947_RCE,CVE-2022-22947反弹shell,CVE-2022-22947 getshell

mrknow001/CVE-2022-22947

github · Created 2022-03-07 16:24:42 UTC · 7 stars

Spring Cloud Gateway Actuator API SpEL Code Injection (CVE-2022-22947)

M0ge/CVE-2022-22947-Spring-Cloud-Gateway-SpelRCE

github · Created 2022-03-07 07:24:13 UTC · 13 stars

Spring Cloud Gateway远程代码执行漏洞POC,基于命令执行的基础上,增加了反弹shell操作

22ke/CVE-2022-22947

github · Created 2022-03-05 06:19:46 UTC · 2 stars

hunzi0/CVE-2022-22947-Rce_POC

github · Created 2022-03-04 14:58:02 UTC · 7 stars

批量url检测Spring-Cloud-Gateway-CVE-2022-22947

nanaao/CVE-2022-22947-POC

github · Created 2022-03-04 11:45:35 UTC · 0 stars

CVE-2022-22947批量检测脚本,回显命令没进行正则,大佬们先用着,后续再更

dbgee/CVE-2022-22947

github · Created 2022-03-04 09:47:55 UTC · 2 stars

Spring Cloud Gateway Actuator API 远程命令执行 CVE-2022-22947

tangxiaofeng7/CVE-2022-22947-Spring-Cloud-Gateway

github · Created 2022-03-04 06:38:26 UTC · 71 stars

CVE-2022-22947批量

Summer177/Spring-Cloud-Gateway-CVE-2022-22947

github · Created 2022-03-04 02:36:02 UTC · 0 stars

Spring Cloud Gateway远程代码执行漏洞

Greetdawn/CVE-2022-22947

github · Created 2022-03-04 02:27:50 UTC · 5 stars

crowsec-edtech/CVE-2022-22947

github · Created 2022-03-03 18:26:18 UTC · 39 stars

Spring Cloud Gateway < 3.0.7 & < 3.1.1 Code Injection (RCE)

Axx8/CVE-2022-22947_Rce_Exp

github · Created 2022-03-03 13:13:02 UTC · 76 stars

Spring Cloud Gateway 远程代码执行漏洞Exp Spring_Cloud_Gateway_RCE_Exp-CVE-2022-22947

lucksec/Spring-Cloud-Gateway-CVE-2022-22947

github · Created 2022-03-02 11:58:55 UTC · 219 stars

CVE-2022-22947

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Detected by Nuclei

  • Detected by Metasploit