DEV Community

Cover image for CVE-2022-22947: VMware Spring Cloud Gateway Code Injection Vulnerability
Freedom Coder
Freedom Coder

Posted on • Originally published at scyscan.com

CVE-2022-22947: VMware Spring Cloud Gateway Code Injection Vulnerability

CVE ID

CVE-2022-22947

Vulnerability Name

VMware Spring Cloud Gateway Code Injection Vulnerability

  • Project: VMware
  • Product: Spring Cloud Gateway

Date

  • Date Added: 2022-05-16
  • Due Date: 2022-06-06

Description

Spring Cloud Gateway applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured.

Known To Be Used in Ransomware Campaigns?

Unknown

Action

Apply updates per vendor instructions.

Additional Notes

https://nvd.nist.gov/vuln/detail/CVE-2022-22947

Related Security News

More CVEs Info

Common Vulnerabilities & Exposures (CVE) List

Top comments (0)