CVE-2022-22947
هجوم حقن كود على spring cloud gateway
ملخص CVE
في إصدارات spring cloud gateway الأقدم من 3.1.1+ و 3.0.7+، تكون التطبيقات عرضة لهجوم حقن كود عند تمكين نقطة نهاية Gateway Actuator وجعلها مكشوفة وغير آمنة. يمكن لمهاجم عن بعد إرسال طلب تم إنشاؤه بشكل ضار قد يسمح بتنفيذ تعليمات برمجية عشوائية عن بُعد على المضيف البعيد.
الإصدارات المتأثرة
- Oracle Commerce Guided Search 11.3.2
- Oracle Communications Cloud Native Core Network Function Cloud Native Environment 1.10.0
- Oracle Communications Cloud Native Core Console 22.2.0
- Oracle Communications Cloud Native Core Network Slice Selection Function 1.8.0
- Oracle Communications Cloud Native Core Network Slice Selection Function 22.1.0
- Oracle Communications Cloud Native Core Security Edge Protection Proxy 22.1.1
- Oracle Communications Cloud Native Core Network Repository Function 1.15.0
- Oracle Communications Cloud Native Core Network Repository Function 1.15.1
- Oracle Communications Cloud Native Core Network Repository Function 22.2.0
- Oracle Communications Cloud Native Core Network Repository Function 22.1.2
- Oracle Communications Cloud Native Core Binding Support Function 1.11.0
- Oracle Communications Cloud Native Core Binding Support Function 22.1.3
- Oracle Communications Cloud Native Core Service Communication Proxy 1.15.0
- Oracle Communications Cloud Native Core Network Exposure Function 22.1.0
- Vmware Spring Cloud Gateway < 3.0.7
- Vmware Spring Cloud Gateway 3.1.0
المراجع