Junglewise Threat Intelligence

CVE-2022-22963: Spring Cloud Function Code Injection with a specially crafted SpEL as a routing expression

CVE-2022-22963 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2022-04-03

Technologies: VMware Spring Cloud Function. Vendors: VMware.

Executive brief

VMware Tanzu Spring Cloud Function contains a remote code execution vulnerability in its routing functionality. An attacker can provide a specially crafted SpEL (Spring Expression Language) as a routing-expression to execute arbitrary code and access local resources.

Affected products

  • VMware Spring Cloud Function 3.1.6, 3.2.2 and older unsupported versions

Timeline

  • 2022-08-25: disclosed
  • 2022-08-25: advisory
  • 2022-08-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog