QID 150494
Date Published: 2022-04-01
QID 150494: Spring Cloud Function Remote Code Execution (RCE) Vulnerability (CVE-2022-22963)
Spring Cloud Function is one of the features of Spring Cloud. It allows developers to write cloud-agnostic functions with Spring features.
On affected versions of Spring Cloud Function it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution.
Affected versions:
Spring Cloud Function versions before 3.1.7
Spring Cloud Function versions before 3.2.3
QID Detection Logic: (Unauthenticated)
The QID sends a HTTP POST request with specially crafted payload inside Request headers, where vulnerable servers will make a DNS query that will trigger Qualys Periscope detection mechanism.
Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary code on the target system.
CVEs related to QID 150494
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Vmware |
|