← Back to browse · API

CVE-2022-22947

Severity
CRITICAL
CVSS
10.0
EPSS
0.98253
Risk score
59.39
CISA KEV
Yes
PoC
No
Published
2022-03-03
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2022-1288, GHSA-3GX9-37WW-9QW6
Products
VMware:Spring Cloud Gateway, VMware:Spring cloud Gateway Spring cloud gateway versions 3.1.x prior to 3.1.1+, 3.0.x prior to 3.0.7+ and all old and unsupported versions
Sources
cisa.gov CVE-2022-22947
euvd EUVD-2022-1288

Description

In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote execution on the remote host.

References