CVE-2022-22963

Description from NVD

In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.

Information Acquisition Date:2022-04-30T16:40Z
CVSS 2.0: 7.5 HIGH CVSS 3.x: 9.8 CRITICAL

▼ CVSS3 Vec CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

▼ CVSS2 Vec AV:N/AC:L/Au:N/C:P/I:P/A:P

NVD References

 https://tanzu.vmware.com/security/cve-2022-22963
     source:MISC
     tags:Vendor Advisory    
 20220401 Vulnerability in Spring Cloud Function Framework Affecting Cisco Products: March 2022
     source:CISCO
     tags:Third Party Advisory    
 https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0005
     source:CONFIRM
     tags:Third Party Advisory    
 https://www.oracle.com/security-alerts/cpuapr2022.html
     source:MISC
     tags:

This vulnerability may involve a PoC.

Refer to Information on External Sites

CVE InfomationExploits or more Infomation
mitreEXPLOIT DATABASE
NVD0day.today
vulmon.comgithub
CVE DetailsTwitter
JVN ENG JPN
Reconshell

Software Tag: Java(3 tweets) Linux(1 tweets) OpenSSL(1 tweets)



List of frequently cited URLs

URLNum of Times Referred to
https://alerts.vulmon.com/?utm_source=twitter&utm_medium=so...206
https://cvetrends.com53
http://cyberiqs.com/latestnews37
https://piyolog.hatenadiary.jp/entry/2022/04/01/06594616
https://lists.astaro.com/ASGV9-IPS-rules.html#014
https://ift.tt/PM4mXY111
https://www.scutum.jp/information/waf_tech_blog/2022/04/waf...10
https://spring.io/blog/2022/03/29/cve-report-published-for-...6
https://tanzu.vmware.com/security/cve-2022-229636
https://www.fastly.com/blog/spring-has-sprung-breaking-down...5
https://www.tarlogic.com/blog/spring4shell-vulnerability-cv...5
https://github.com/dinosn/CVE-2022-229634
https://tonernews.com/forums/topic/notice-of-the-potential-...4
https://www.citrix.com/blogs/2022/04/01/guidance-for-reduci...4
https://www.cyberkendra.com/2022/03/springshell-rce-0-day-v...4
http://earmas.ga3
https://vuldb.com/?ctiid.1960703
https://sysdig.com/blog/cve-2022-22963-spring-cloud3
https://opsmtrs.com/3fTgB6p3
https://twitter.com/bytehx343/status/15090345393307320333
https://bugalert.org/content/notices/2022-03-29-spring.html3
https://threatpost.com/critical-rce-bug-spring-log4shell/17...3
https://www.lunasec.io/docs/blog/spring-rce-vulnerabilities3
https://www.greynoise.io/viz/tag/spring-cloud-function-spel...3
https://www.jpcert.or.jp/newsflash/2022040101.html3
https://www.kitploit.com/2022/03/cve-2022-22963-poc-spring-...3
https://securityboulevard.com/2022/03/update-on-0-day-vulne...3
https://ipssignatures.appspot.com/?cve=CVE-2022-229633

▼ Show Information from Twitter(18)


List of frequently cited URLs

URLNum of Times Referred to
alerts.vulmon.com206
cvetrends.com53
cyberiqs.com37
piyolog.hatenadiary.jp16
lists.astaro.com14
ift.tt11
www.scutum.jp10
spring.io6
tanzu.vmware.com6
www.fastly.com5
www.tarlogic.com5
github.com4
tonernews.com4
www.citrix.com4
www.cyberkendra.com4
earmas.ga3
vuldb.com3
sysdig.com3
opsmtrs.com3
twitter.com3
bugalert.org3
threatpost.com3
www.lunasec.io3
www.greynoise.io3
www.jpcert.or.jp3
www.kitploit.com3
securityboulevard.com3
ipssignatures.appspot.com3

▼ Show Information from Twitter(18)


GitHub Search Results: Up to 10
NameURL
dinosn/CVE-2022-22963 https://github.com/dinosn/CVE-2022-22963
darryk10/CVE-2022-22963 https://github.com/darryk10/CVE-2022-22963
hktalent/spring-spel-0day-poc https://github.com/hktalent/spring-spel-0day-poc
jschauma/check-springshell https://github.com/jschauma/check-springshell
exploitbin/CVE-2022-22963-Spring-Core-RCE https://github.com/exploitbin/CVE-2022-22963-Spring-Core-RCE
SealPaPaPa/SpringCloudFunction-Research https://github.com/SealPaPaPa/SpringCloudFunction-Research
k3rwin/spring-cloud-function-rce https://github.com/k3rwin/spring-cloud-function-rce
AayushmanThapaMagar/CVE-2022-22963 https://github.com/AayushmanThapaMagar/CVE-2022-22963
Anonymous-ghost/AttackWebFrameworkTools-5.0 https://github.com/Anonymous-ghost/AttackWebFrameworkTools-5.0
XuCcc/VulEnv https://github.com/XuCcc/VulEnv

GitHub Search Results: Up to 10
NameURL
dinosn/CVE-2022-22963 github.com
darryk10/CVE-2022-22963 github.com
hktalent/spring-spel-0day-poc github.com
jschauma/check-springshell github.com
exploitbin/CVE-2022-22963-Spring-Core-RCE github.com
SealPaPaPa/SpringCloudFunction-Research github.com
k3rwin/spring-cloud-function-rce github.com
AayushmanThapaMagar/CVE-2022-22963 github.com
Anonymous-ghost/AttackWebFrameworkTools-5.0 github.com
XuCcc/VulEnv github.com

2023/04/06 Score : 0
Added Har-sia Database : 2022/03/30
Last Modified : 2023/04/06
Highest Scored Date : 2022/03/31
Highest Score : 239