CVE-2022-22947
critical-risk
Published 2022-03-03
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote execution on the remote host.
Do I need to act?
!
94.5% chance of exploitation in next 30 days
EPSS score — higher than 6% of all CVEs
!
CISA KEV: actively exploited in the wild
On the Known Exploited Vulnerabilities catalog — federal agencies must patch
!
1 public exploit available
+
Fix available
Upgrade to: 2b4b39598dbbb7baa8426a283050a5b9490bb28b
10
CVSS 10.0/10
Critical
NETWORK
/ LOW complexity
Affected Products (16)
References (11)
US Government Resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-...
78
/ 100
critical-risk
Severity
33/34 · Critical
Exploitability
27/34 · High
Exposure
18/34 · Moderate