Description
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
Published: 2022-04-01
Score: 9.8 Critical
EPSS: 94.5% High
KEV: Yes
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-6v73-fgf6-w5j7 Spring Cloud Function Code Injection with a specially crafted SpEL as a routing expression
History

Wed, 22 Oct 2025 00:30:00 +0000


Tue, 21 Oct 2025 20:30:00 +0000


Tue, 21 Oct 2025 19:30:00 +0000


Wed, 29 Jan 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2022-08-25'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 14 Aug 2024 01:00:00 +0000

Type Values Removed Values Added
References

Subscriptions

Oracle Banking Branch Banking Cash Management Banking Corporate Lending Process Management Banking Credit Facilities Process Management Banking Electronic Data Exchange For Corporates Banking Liquidity Management Banking Origination Banking Supply Chain Finance Banking Trade Finance Process Management Banking Virtual Account Management Communications Cloud Native Core Automated Test Suite Communications Cloud Native Core Console Communications Cloud Native Core Network Exposure Function Communications Cloud Native Core Network Function Cloud Native Environment Communications Cloud Native Core Network Repository Function Communications Cloud Native Core Network Slice Selection Function Communications Cloud Native Core Policy Communications Cloud Native Core Security Edge Protection Proxy Communications Cloud Native Core Unified Data Repository Communications Communications Policy Management Financial Services Analytical Applications Infrastructure Financial Services Behavior Detection Platform Financial Services Enterprise Case Management Mysql Enterprise Monitor Product Lifecycle Analytics Retail Xstore Point Of Service Sd-wan Edge
Redhat Serverless
Vmware Spring Cloud Function
cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published:

Updated: 2025-10-21T23:15:42.941Z

Reserved: 2022-01-10T00:00:00.000Z

Link: CVE-2022-22963

cve-icon Vulnrichment

Updated: 2024-08-03T03:28:42.845Z

cve-icon NVD

Status : Analyzed

Published: 2022-04-01T23:15:13.663

Modified: 2025-10-30T19:56:53.730

Link: CVE-2022-22963

cve-icon Redhat

Severity : Critical

Publid Date: 2022-03-29T00:00:00Z

Links: CVE-2022-22963 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses