Impact
The JsonToGrpcGatewayFilterFactory in Spring Cloud Gateway allows a user to supply an arbitrary Spring Resource location for defining a gRPC proto descriptor. This flaw enables retrieval of data from any network location, including internal services or an attacker‑controlled server, and permits reading of local files that the gateway process can access. The vulnerability thus facilitates server‑side request forgery (SSRF) as well as local file read, potentially exposing sensitive data and facilitating further attacks.
Affected Systems
Spring Cloud Gateway (Spring) versions 5.0.0 through 5.0.2, 4.3.0 through 4.3.5, 4.0.0 through 4.2.9, and all releases up to 3.1.13 are affected. Any installation of these versions that uses the JsonToGrpcGatewayFilterFactory is therefore at risk.
Risk and Exploitability
The CVSS base score of 7.7 signifies a high‑severity flaw. The EPSS score of < 1 % indicates a low probability of exploitation, yet the SSRF characteristic means attackers could still use the gateway’s public or internal interfaces to reach arbitrary network destinations. The vulnerability is not listed in the CISA KEV catalog, implying no publicly known exploits at the time of this analysis. Nevertheless, the high score and the nature of the vulnerability warrant prompt attention.
OpenCVE Enrichment