Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2022-22947 — Spring-Cloud-Spel-RCE | Kitploit
Tools/GitHubGitHub/4nnns/cve-2022-22947
Vulnerability AnalysisCode AnalysisExploitationWeb Application ExploitationLearning & EducationLabs & Practice
GitHub4nnns/cve-2022-22947

CVE-2022-22947

Spring-Cloud-Spel-RCE

View Repository
122174 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

SpringCloud-Gateway Command Execution Vulnerability (CVE-2022-22947)

Environment Setup

Method 1:

Clone the ready environment code from GitHub.

GitHub Repository

//⚠️Note: The environment code download path must not contain Chinese characters or spaces
git clone https://github.com/Ha0Liu/CVE-2022-22947.git

Open the downloaded code package with IDEA: Open ---> Path of downloaded file ---> Open.

Method 2:

Create a project manually and set up the environment.

(1) Create a new project, configure it and click Next all the way through;

(2) Analyze the project directory structure:

  • The .idea folder contains IntelliJ IDEA default configuration files with no other use; can be deleted or retained as needed.
  • The src folder is the main code area for the entire project, which includes two subfolders: java and resources. java is the area for writing Java code in the project, and resources is the configuration area for the entire project. By default, Spring projects add the SpringApplication method in java, which is the default startup method for Spring. The resources folder contains application.properties by default, which is the configuration file for the Spring project.
  • The test folder is for testing; test methods can be placed here.
  • pom.xml is the Maven configuration file, including dependencies, configurations, etc. needed for the project.
  • The .iml file is the Maven dependency package configuration, also added by default.
  • The External Libraries folder contains all dependency packages for the project.

(3) Add Maven dependencies to the pom.xml file (the Maven Repository contains details of all dependencies).

  • Part of the XML code is generated by default in the pom file, details as follows:

  • Import the dependencies needed for the project. Since this is a SpringBoot project, you need to import the spring-boot-starter dependency as the server starter. Furthermore, because this vulnerability is in the Gateway of SpringCloud, the vulnerable version is below 3.1.1. Therefore, we use version 3.1.0 for reproduction. Also, we need to monitor and access the gateway through the actuator interface, so we also need this dependency. The specific contents are as follows:

(4) Modify the Spring configuration file (path: src → main → resources → application.properties), details as follows:

  • server.port is the startup port of the Spring server, default is 8080. You can set it according to your needs.
  • management.endpoint.gateway.enabled=true enables the actuator endpoint to detect the SpringCloud-Gateway gateway. The default is false. Since this vulnerability requires monitoring the state of the gateway, we need to manually change it to true to enable monitoring.
  • management.endpoints.web.exposure.include=gateway selects the server gateway as the Gateway gateway. Since this vulnerability is a Gateway gateway vulnerability, we declare in the configuration file to select the Gateway gateway.

(5) Modify the automatically generated Java class after creating the new project (class name is usually ProjectName + Application, path: src → main → java → com.xxx.xxx → xxxApplication). See the figure below for details:

(6) Start the project, as shown below:

(7) Access http://localhost:9000. If the page is consistent with the screenshot, the environment setup is successful.

Reverse Audit

(1) First, let's look at the official fix patch, diff as follows: https://github.com/spring-cloud/spring-cloud-gateway/commit/337cef276bfd8c59fb421bfe7377a9e19c68fe1e . In the function org.springframework.cloud.gateway.support.ShortcutConfigurable#getValue, the official replaced StandardEvaluationContext with GatewayEvaluationContext to execute SPEL expressions.

From the figure above, we can see that this patch mainly modifies the parsing method of SPEL expressions. Line 66 shows an if statement indicating that the SPEL expression must start with #{ and end with }. The getValue method performs SPEL expression parsing, indicating that this vulnerability is an RCE vulnerability triggered by SPEL expressions.

(2) Click on the getValue field while holding Ctrl (or Control + left mouse click) to backtrack and find the enumeration org.springframework.cloud.gateway.support.ShortcutConfigurable.ShortcutType.

From the default method above, we can see that the DEFAULT method in the enumeration is called. The method details are as follows:

default ShortcutType shortcutType() {
		return ShortcutType.DEFAULT;
	}

DEFAULT method

(3) Backtrack further to find org.springframework.cloud.gateway.support.ConfigurationService.class#normalizeProperties().

This normalizeProperties() method parses the properties of the filter, passing the filter's configuration properties into normalize, and finally enters getValue to execute the SPEL expression, causing SPEL injection.

Forward Audit (Blind Exploit Chain)

(1) According to the documentation [https://cloud.spring.io/spring-cloud-gateway/multi/multi__actuator_api.html](https://cloud.spring.io/spring-cloud-gateway/multi/multi actuator_api.html ), users can create and delete routes in the gateway via actuator. The figure below shows the basic structure of the gateway.

(2) In IDEA, you can use the actuator's mapping feature to find the functional interfaces for gateway creation, deletion, etc.

(3) Trace to the RouteDefinition class, which declares the structure of the gateway.

Download Tool