CISA Known Exploited Vulnerability

CVE-2022-22947

VMware · Spring Cloud Gateway

VMware Spring Cloud Gateway Code Injection Vulnerability

Date added
BOD 22-01 due date
CWE CWE-94
Ransomware Unknown

CISA description

Spring Cloud Gateway applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured.

Required action

Apply updates per vendor instructions.