QID 376520
Date Published: 2022-04-06
QID 376520: Spring Cloud Function Remote Code Execution (RCE) Vulnerability Scan Utility
A Remote Code Execution(RCE) Vulnerability exists in the Spring Cloud Function by a malicious Spring Expression.
Affected Versions:
Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions.
QID Detection: (Authenticated) - Windows
This QID reads the file generated by Qualys utility Qualys Spring4scanwin Scan Utility for Windows
The QID reads 1st 100000 characters from the generated output file.
QID Detection: (Authenticated) - Linux
This QID reads the file generated by Qualys utility Qualys Spring4scanlinuxScan Utility for Linux to find vulnerable instances of Spring Cloud Function.
By using routing functionality, it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
Customers are advised to visit Spring Cloud Function RCE for more information on this.
- RCE in Spring Cloud Function -
tanzu.vmware.com/security/cve-2022-22963
CVEs related to QID 376520
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Spring Cloud Function |
|