Description


In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote execution on the remote host.

Related CPE's


a

vmware

spring_cloud_gateway

2


a

oracle

communications_cloud_native_core_binding_support_function

2




a

oracle

communications_cloud_native_core_network_repository_function

4

a

oracle

communications_cloud_native_core_network_slice_selection_function

2


Weaknesses



CWE-94


CWE-917

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

10 · Critical

  • CVSS V3.1

  • CVSS V3.0

  • CVSS V2.0

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2022-03-03T22:15:08.673

3 years ago

Last modified

2025-03-13T15:40:47.357

1 month ago