QID 730418
Date Published: 2022-04-01
QID 730418: Spring Cloud Function Remote Code Execution (RCE) Vulnerability (Unauthenticated Check)
A Remote Code Execution(RCE) Vulnerability exists in the Spring Cloud Function by a malicious Spring Expression.
Affected Versions:
Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions.
QID Detection: (Unauthenticated)
This QID checks for vulnerable Spring Cloud Application by sending a crafted payload to the webserver
Note: This QID utilizes utilities like nc, telnet, curl, wget, powershell etc to check for vulnerable spring cloud server.
By using routing functionality, it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
Solution
For more information about the vulnerability please refer to
Spring Cloud Function RCE for more information on this.
Vendor References
- RCE in Spring Cloud Function -
tanzu.vmware.com/security/cve-2022-22963
CVEs related to QID 730418
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Spring Cloud Function |
|