Executive brief
VMware Tanzu Spring Cloud Function contains a remote code execution vulnerability in its routing functionality. An attacker can provide a specially crafted SpEL (Spring Expression Language) as a routing-expression to execute arbitrary code and access local resources.
Affected products
- VMware Spring Cloud Function 3.1.6, 3.2.2 and older unsupported versions
Timeline
- 2022-08-25: disclosed
- 2022-08-25: advisory
- 2022-08-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog