QID 150494

Date Published: 2022-04-01

QID 150494: Spring Cloud Function Remote Code Execution (RCE) Vulnerability (CVE-2022-22963)

Spring Cloud Function is one of the features of Spring Cloud. It allows developers to write cloud-agnostic functions with Spring features.

On affected versions of Spring Cloud Function it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution.

Affected versions:
Spring Cloud Function versions before 3.1.7
Spring Cloud Function versions before 3.2.3

QID Detection Logic: (Unauthenticated)
The QID sends a HTTP POST request with specially crafted payload inside Request headers, where vulnerable servers will make a DNS query that will trigger Qualys Periscope detection mechanism.

Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary code on the target system.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to upgrade to the Spring Cloud Function 3.1.7, 3.2.3 or later version to remediate this vulnerability. For more information refer Security Advisory

    CVEs related to QID 150494

    Software Advisories
    Advisory ID Software Component Link
    Vmware URL Logo tanzu.vmware.com/security/cve-2022-22963