CVE-2022-22963

All FrameworksSpring FrameworkCWE-94CVE-2022-22963

CVE-2022-22963

State: PUBLISHED · Published: 2022-04-01 · Updated: 2025-10-21 · Assigner: vmware
Description
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2022/22xxx/CVE-2022-22963.json