CISA Known Exploited Vulnerability

CVE-2022-22963

VMware Tanzu · Spring Cloud

VMware Tanzu Spring Cloud Function Remote Code Execution Vulnerability

Date added
BOD 22-01 due date
CWE CWE-94
Ransomware Unknown

CISA description

When using routing functionality in VMware Tanzu's Spring Cloud Function, it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.

Required action

Apply updates per vendor instructions.