CVE-2022-22963: VMware Tanzu Spring Cloud Function Remote Code Execution Vulnerability
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
Other sources
When using routing functionality in VMware Tanzu's Spring Cloud Function, it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
— CISA
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-22963.
What is the title of the vulnerability?
The title of the vulnerability is VMware Tanzu Spring Cloud Function Remote Code Execution Vulnerability.
What is the description of the vulnerability?
The vulnerability allows a user to provide a specially crafted SpEL as a routing-expression in VMware Tanzu's Spring Cloud Function, which may result in remote code execution and access to local resources.
Which software is affected by the vulnerability?
The vulnerability affects VMware Tanzu Spring Cloud.
Is there a reference link for more information?
Yes, you can find more information about the vulnerability at https://tanzu.vmware.com/security/cve-2022-22963.