CVE-2022-22947:Spring Cloud Gateway 代码注入漏洞
blog.viettelcybersecurity.com | 漏洞 | CVE-2022-22947 | #cloud | #rce | #zero-day | #java | #vulnerability | #cve-2022-22947 | #spring-cloud-gateway | #el-injection
摘要
Viettel 研究员详解 Spring Cloud Gateway 0-day(CVE-2022-22947):暴露的 actuator 端点可被用于添加携带 SpEL 表达式的路由,经 EL 注入最终实现 RCE。
- 发布时间
- 收录时间
Skip to content