Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions are susceptible to remote code execution vulnerabilities. When using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
View the template here CVE-2022-22963.yaml
Lab | Machine | Link |
---|---|---|
Hack The Box | Inject | Go to Practice |
References:
https://github.com/cckuailong/spring-cloud-function-SpEL-RCE