Code Injection in Spring Cloud Gateway - CVE-2022-22947
Published: March 3, 2022 / Updated: June 21, 2024
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a code injection attack when the Gateway Actuator endpoint is enabled. A remote attacker can send a specially crafted HTTP POST request and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Oracle Communications Cloud Native Core Network Exposure Function
Oracle Communications Cloud Native Core Network Repository Function
Oracle Communications Cloud Native Core Binding Support Function
Oracle Communications Cloud Native Core Network Slice Selection Function
Oracle Communications Cloud Native Core Security Edge Protection Proxy
Oracle Communications Cloud Native Core Console
How to mitigate CVE-2022-22947
Links to Public Exploits and PoC-codes
- Exploit #10082 - CVE-2022-22947 (CVE-2022-22947 exploit script) (June 21, 2024)
- Exploit #9098 - CVE-2022-22947-Spring-Cloud-Gateway-SpelRCE (Spring Cloud Gateway远程代码执行漏洞POC,基于命令执行的基础上,增加了反弹shell操作) (June 8, 2023)
- Exploit #9087 - CVE-2022-22947 (Spring Cloud Gateway Actuator API SpEL表达式注入命令执行Exp) (June 3, 2023)
- Exploit #9064 - CVE-2022-22947 (CVE-2022-22947注入哥斯拉内存马) (May 11, 2023)
- Exploit #8789 - CVE-2022-22947-Rce_POC (批量url检测Spring-Cloud-Gateway-CVE-2022-22947) (February 1, 2023)
- Exploit #8611 - CVE-2022-22947 () (November 15, 2022)
- Exploit #8606 - Burp_VulPscan (burp被动扫描插件,目前只有CVE-2022-22947) (November 14, 2022)
- Exploit #8526 - CVE-2022-22947 () (October 23, 2022)
- Exploit #8461 - Spring Cloud Gateway Remote Code Execution (October 12, 2022)
- Exploit #8282 - CVE-2022-22947 () (August 23, 2022)
- Exploit #8212 - CVE-2022-22947 () (August 3, 2022)
- Exploit #8176 - CVE-2022-22947_exp (CVE-2022-22947 Exploit script) (July 24, 2022)
- Exploit #8013 - CVE-2022-22947-POC (批量检测Spring Cloud Gateway 远程代码执行漏洞 Spring_Cloud_Gateway_RCE_POC-CVE-2022-22947) (June 9, 2022)
- Exploit #8003 - CVE-2022-22947-POC (批量检测Spring Cloud Gateway 远程代码执行漏洞 Spring_Cloud_Gateway_RCE_POC-CVE-2022-22947) (June 9, 2022)
- Exploit #7911 - CVE-2022-22947-exp () (May 29, 2022)
- Exploit #7864 - CVE-2022-22947_EXP (一个可单独、批量验证的脚本,也可以反弹shell) (May 19, 2022)
- Exploit #7851 - CVE-2022-22947- (Spring Cloud Gateway Actuator API SpEL表达式注入命令执行(CVE-2022-22947) 注入哥斯拉内存马) (May 17, 2022)
- Exploit #7807 - Spring Cloud Gateway 3.1.0 - Remote Code Execution (RCE) (May 13, 2022)
- Exploit #7692 - cve-2022-22947-godzilla-memshell (CVE-2022-22947 注入Godzilla内存马) (April 26, 2022)
- Exploit #7659 - CVE-2022-22947-exp () (April 15, 2022)
- Exploit #7573 - springcloudRCE (Spring Cloud Gateway RCE - CVE-2022-22947 ) (April 1, 2022)
- Exploit #7552 - CVE-2022-22947-exp () (March 30, 2022)
- Exploit #7548 - CVE-2022-22947 () (March 30, 2022)
- Exploit #7543 - CVE-2022-22947 (Spring Cloud Gateway < 3.0.7 & < 3.1.1 Code Injection (RCE)) (March 27, 2022)
- Exploit #7542 - CVE-2022-22947 (poc for CVE-2022-22947) (March 27, 2022)
- Exploit #7523 - spring_cloud_gateway_memshell (CVE-2022-22947 memshell) (March 20, 2022)
- Exploit #7516 - CVE-2022-22947 (CVE-2022-22947_POC_EXP) (March 17, 2022)
- Exploit #7485 - spring-cloud-gateway-rce (spring-cloud-gateway-rce CVE-2022-22947) (March 14, 2022)
- Exploit #7477 - Spring-CVE-2022-22947- () (March 10, 2022)
- Exploit #7473 - CVE-2022-22947-Spring-Cloud () (March 10, 2022)
- Exploit #7470 - CVE-2022-22947-exp (CVE-2022-22947 Exploit script) (March 10, 2022)
- Exploit #7452 - CVE-2022-22947 (CVE-2022-22947_EXP,CVE-2022-22947_RCE,CVE-2022-22947反弹shell,CVE-2022-22947 getshell) (March 8, 2022)
- Exploit #7433 - CVE-2022-22947-Spring-Cloud-Gateway-SpelRCE (Spring Cloud Gateway远程代码执行漏洞POC,基于命令执行的基础上,增加了反弹shell操作) (March 7, 2022)
- Exploit #7432 - CVE-2022-22947 (SpringCloudGatewayRCE / Code By:Jun_sheng) (March 7, 2022)
- Exploit #7431 - cve-2022-22947 () (March 7, 2022)
- Exploit #7430 - CVE-2022-22947 (Spring Cloud Gateway Actuator API SpEL Code Injection (CVE-2022-22947)) (March 7, 2022)
- Exploit #7427 - cve-2022-22947 (poc for cve-2022-22947) (March 5, 2022)
- Exploit #7426 - Spring-Cloud-Gateway-CVE-2022-22947 (Spring Cloud Gateway远程代码执行漏洞) (March 5, 2022)
- Exploit #7425 - CVE-2022-22947 () (March 5, 2022)
- Exploit #7424 - CVE-2022-22947 (Exp) (March 5, 2022)
- Exploit #7423 - cve-2022-22947 (Spring-Cloud-Gateway-CVE-2022-22947) (March 5, 2022)
- Exploit #7422 - -cve-2022-22947- ( cve-2022-22947 spring cloud gateway 批量扫描脚本) (March 5, 2022)
- Exploit #7421 - CVE-2022-22947 (Spring Cloud Gateway Actuator API SpEL Code Injection.) (March 5, 2022)
- Exploit #7420 - CVE-2022-22947-goby (日常更新一些顺手写的gobypoc,包含高危害EXP) (March 5, 2022)
- Exploit #7419 - CVE-2022-22947-Spring-Cloud-Gateway (CVE-2022-22947批量) (March 5, 2022)
- Exploit #7418 - CVE-2022-22947-POC (CVE-2022-22947批量检测脚本,超时时间不超过2s,已更新可反弹shell的EXP,欢迎师傅们试用) (March 5, 2022)
- Exploit #7417 - CVE-2022-22947 () (March 5, 2022)
- Exploit #7415 - CVE-2022-22947-Rce_POC (批量url检测Spring-Cloud-Gateway-CVE-2022-22947) (March 5, 2022)
- Exploit #7413 - CVE-2022-22947-RCE (CVE-2022-22947 RCE) (March 3, 2022)
- Exploit #7412 - cve-2022-22947 (poc for cve-2022-22947) (March 3, 2022)
- Exploit #7411 - CVE-2022-22947_Rce_Exp (Spring Cloud Gateway 远程代码执行漏洞Exp Spring_Cloud_Gateway_RCE_Exp-CVE-2022-22947) (March 3, 2022)
- Exploit #7409 - Spring_CVE_2022_22947 (Spring_CVE_2022_22947:Spring Cloud Gateway现高风险漏洞cve,poc漏洞利用,一键利用,开箱即用) (March 3, 2022)
- Exploit #7408 - spring-cve-2022-22947 (Spring cloud gateway code injection : CVE-2022-22947) (March 3, 2022)
- Exploit #7407 - CVE-2022-22947 (Spring Cloud Gateway < 3.0.7 & < 3.1.1 Code Injection (RCE)) (March 3, 2022)
- Exploit #7406 - SpringCloudGatewayRCE (SpringCloudGatewayRCE - CVE-2022-22947 / Code By:Tas9er) (March 3, 2022)
- Exploit #7405 - Spring-Cloud-Gateway-CVE-2022-22947 (CVE-2022-22947) (March 3, 2022)
External References
Related Security Bulletins
- Multiple vulnerabilities in VMware Spring Cloud Gateway
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Network Slice Selection Function
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Network Exposure Function
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Security Edge Protection Proxy
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Network Repository Function
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Console
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Binding Support Function