CVE-2022-22947
Ein Code-Injection-Angriff auf Spring Cloud Gateway
Zusammenfassung der CVE
Bei Spring Cloud Gateway-Versionen vor 3.1.1+ und 3.0.7+ sind Anwendungen anfällig für einen Code-Injection-Angriff, wenn der Gateway-Actuator-Endpoint aktiviert, exponiert und ungesichert ist. Ein entfernter Angreifer könnte eine böswillig gestaltete Anfrage stellen, die eine beliebige Remote-Ausführung auf dem entfernten Host ermöglichen könnte.
Betroffene Versionen
- Oracle Commerce Guided Search 11.3.2
- Oracle Communications Cloud Native Core Network Function Cloud Native Environment 1.10.0
- Oracle Communications Cloud Native Core Console 22.2.0
- Oracle Communications Cloud Native Core Network Slice Selection Function 1.8.0
- Oracle Communications Cloud Native Core Network Slice Selection Function 22.1.0
- Oracle Communications Cloud Native Core Security Edge Protection Proxy 22.1.1
- Oracle Communications Cloud Native Core Network Repository Function 1.15.0
- Oracle Communications Cloud Native Core Network Repository Function 1.15.1
- Oracle Communications Cloud Native Core Network Repository Function 22.2.0
- Oracle Communications Cloud Native Core Network Repository Function 22.1.2
- Oracle Communications Cloud Native Core Binding Support Function 1.11.0
- Oracle Communications Cloud Native Core Binding Support Function 22.1.3
- Oracle Communications Cloud Native Core Service Communication Proxy 1.15.0
- Oracle Communications Cloud Native Core Network Exposure Function 22.1.0
- Vmware Spring Cloud Gateway < 3.0.7
- Vmware Spring Cloud Gateway 3.1.0
Referenzen