In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote execution on the remote host.
CVE Infomation | Exploits or more Infomation |
---|---|
mitre | EXPLOIT DATABASE |
NVD | 0day.today |
vulmon.com | github |
CVE Details | |
JVN ENG JPN | |
Reconshell |
Software Tag:
List of frequently cited URLs
User | URL | Info Source | Date |
---|---|---|---|
wdahlenb | https://wya.pl/2022/02/26/cve-2022-22947-spel-casting-and-e... | Source wdahlenb 1615105598613520388 | 2023/01/17 |
wdahlenb | https://twitter.com/PortSwiggerRes/status/1614990050994933760 | Source wdahlenb 1615105598613520388 | 2023/01/17 |
List of frequently cited URLs
URL | Num of Times Referred to |
---|---|
cvetrends.com | 55 |
github.com | 28 |
lists.astaro.com | 19 |
www.vulnmachines.com | 11 |
t.me | 6 |
wya.pl | 4 |
cybersecurity.att.com | 4 |
twitter.com | 3 |
www.cisa.gov | 3 |
tanzu.vmware.com | 3 |
ipssignatures.appspot.com | 3 |
User | URL | Info Source |
---|---|---|
wdahlenb | wya.pl | Show Tweet |
wdahlenb | twitter.com | Show Tweet |
Name | URL |
---|---|
lucksec/Spring-Cloud-Gateway-CVE-2022-22947 | https://github.com/lucksec/Spring-Cloud-Gateway-CVE-2022-22947 |
Axx8/CVE-2022-22947_Rce_Exp | https://github.com/Axx8/CVE-2022-22947_Rce_Exp |
tangxiaofeng7/CVE-2022-22947-Spring-Cloud-Gateway | https://github.com/tangxiaofeng7/CVE-2022-22947-Spring-Cloud-Gateway |
dingxiao77/-cve-2022-22947- | https://github.com/dingxiao77/-cve-2022-22947- |
scopion/cve-2022-22947 | https://github.com/scopion/cve-2022-22947 |
chaosec2021/CVE-2022-22947-POC | https://github.com/chaosec2021/CVE-2022-22947-POC |
carlosevieira/CVE-2022-22947 | https://github.com/carlosevieira/CVE-2022-22947 |
Vulnmachines/spring-cve-2022-22947 | https://github.com/Vulnmachines/spring-cve-2022-22947 |
Tas9er/SpringCloudGatewayRCE | https://github.com/Tas9er/SpringCloudGatewayRCE |
wjl110/Spring_CVE_2022_22947 | https://github.com/wjl110/Spring_CVE_2022_22947 |
Name | URL |
---|---|
lucksec/Spring-Cloud-Gateway-CVE-2022-22947 | github.com |
Axx8/CVE-2022-22947_Rce_Exp | github.com |
tangxiaofeng7/CVE-2022-22947-Spring-Cloud-Gateway | github.com |
dingxiao77/-cve-2022-22947- | github.com |
scopion/cve-2022-22947 | github.com |
chaosec2021/CVE-2022-22947-POC | github.com |
carlosevieira/CVE-2022-22947 | github.com |
Vulnmachines/spring-cve-2022-22947 | github.com |
Tas9er/SpringCloudGatewayRCE | github.com |
wjl110/Spring_CVE_2022_22947 | github.com |