CVE-2022-22947

Spring Cloud Gateway

Published 3 Mar 2022 · updated 17 Jun 2026 · Analyzed

10.0 Critical · CVSS 3.1, NVD

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 16 May 2022, with a remediation deadline of 6 Jun 2022 for US federal agencies.

Required action: Apply updates per vendor instructions.

Description

In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote execution on the remote host.

References