CVE-2022-22947

VMware Spring Cloud Gateway Code Injection Vulnerability

10.0
CVSS 3.1
98.3 %
EPSS (current)
2022-05-16
KEV addition
No
Ransomware

Timeline

Publication, first public exploit and KEV addition on a day axis.

Key facts

Vendor / product: VMware / Spring Cloud Gateway

Published: 2022-03-03 · Due (CISA): 2022-06-06

CWE: CWE-917 · EU list: no

Exploit references (metadata only)

SourceReferenceTitleDate
nucleihttp/cves/2022/CVE-2022-22947.yamlSpring Cloud Gateway Code Injection–
metasploitexploit/linux/http/spring_cloud_gateway_rceexploit/linux/http/spring_cloud_gateway_rce2022-01-26
exploitdb50799Spring Cloud Gateway 3.1.0 - Remote Code Execution (RCE)2022-03-07

References only — no downloads or instructions.

Sources