Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-16402
HistoryMar 03, 2022 - 12:00 a.m.

Spring Cloud Gateway Remote Code Execution Vulnerability

2022-03-0300:00:00
China National Vulnerability Database
www.cnvd.org.cn
25
spring cloud gateway
remote code execution
vulnerability
actuator endpoint
code injection
attacks
remote request
arbitrary
remote host
cnvd

EPSS

0.975

Percentile

100.0%

Spring Cloud GateWay is a library provided for building API gateways on top of Spring WebFlux.A remote code execution vulnerability exists in Spring Cloud Gateway, which occurs in the Actuator endpoint of the Spring Cloud Gateway application, which is enabled, public and insecure, is vulnerable to code injection attacks. An attacker could exploit this vulnerability by maliciously creating a remote request that allows arbitrary remote requests to be executed on a remote host.