CVE-2022-22963
Spring Cloud Function Code Injection with a specially crafted SpEL as a routing expression
CVEs:CVE-2022-22963
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 7 are already weaponised in the wild — see the Exploited section.
The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.
Spring Cloud Function Code Injection with a specially crafted SpEL as a routing expression
CVEs:CVE-2022-22963
Remote Code Execution in Spring Framework
CVEs:GHSA-36p3-wjmg-h94x
Remote Code Execution in Spring Framework
CVEs:CVE-2022-22965
Spring Cloud Gateway vulnerable to Code Injection when Gateway Actuator endpoint enabled, exposed, unsecured
CVEs:GHSA-3gx9-37ww-9qw6
Spring Cloud Gateway vulnerable to Code Injection when Gateway Actuator endpoint enabled, exposed, unsecured
CVEs:CVE-2022-22947
GHSA-28g5-j6gh-p2vw
CVEs:GHSA-28g5-j6gh-p2vw
CVEs:CVE-2022-22946
Allocation of Resources Without Limits or Throttling in Spring Framework
CVEs:CVE-2022-22950
Path Traversal in Spring-integration-zip
CVEs:CVE-2021-22114
Path Traversal in Spring-integration-zip
CVEs:GHSA-vw83-h3mq-3qwj
CVEs:CVE-2021-22100
GHSA-hpw7-xrjw-4cx3
CVEs:GHSA-hpw7-xrjw-4cx3
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.