CVE Published: 03/03/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: vmware |
Vendor: n/a |
Product: Spring Cloud Gateway Status : PUBLISHED
CVE-2022-22947 Description
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote execution on the remote host.