CVE Published: 01/04/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: vmware |
Vendor: n/a |
Product: Spring Cloud Function Status : PUBLISHED
CVE-2022-22963 Description
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.