In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote execution on the remote host.
Is CVE-2022-22947 exploited?
Listed in the CISA KEV catalog on 2022-05-16.
Federal remediation due 2022-06-06.
Past that date by 1531 days.
EPSS puts exploitation in the next 30 days at 98%.
Public exploit code: packaged in a public tool.
Public detection rules exist.
Which products and versions are affected?
No affected package list recorded here yet.
Is there a patch?
No patch identifier recorded here yet.
What PlainSec published about CVE-2022-22947
PlainSec has not published a story about this CVE.