Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:34884
HistoryMar 31, 2022 - 1:51 a.m.

Remote Code Execution

2022-03-3101:51:42
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
110

0.975 High

EPSS

Percentile

100.0%

spring-cloud-function-context is vulnerable to remote code execution. The routing functionality allows a user to provide a malicious SpEL as a routing-expression which would allow arbitrary OS commands to be executed remotely.