Impact
The JsonToGrpcGatewayFilterFactory in Spring Cloud Gateway allows a user to supply an arbitrary Spring Resource location for defining a gRPC proto descriptor. This flaw enables retrieval of data from any network location, including internal services or an attacker‑controlled server, and permits reading of local files that the gateway process can access. The vulnerability thus facilitates server‑side request forgery (SSRF) as well as local file read, potentially exposing sensitive data and facilitating further attacks.
Affected Systems
Spring Cloud Gateway (Spring) versions 5.0.0 through 5.0.2, 4.3.0 through 4.3.5, 4.0.0 through 4.2.9, and all releases up to 3.1.13 are affected. Any installation of these versions that uses the JsonToGrpcGatewayFilterFactory is therefore at risk.
Risk and Exploitability
The CVSS base score of 7.7 signifies a high‑severity flaw. Although an EPSS score is not available and the vulnerability is not currently listed in the CISA KEV catalog, the SSRF characteristic implies that attackers could exploit the gateway’s public or internal interfaces to reach arbitrary network destinations. The lack of a KEV listing indicates no publicly known exploits at the time of this analysis, yet the high score and the nature of the vulnerability warrant prompt attention.
OpenCVE Enrichment