
Spring-Cloud-Spel-RCE
Clone the ready environment code from GitHub.
//⚠️Note: The environment code download path must not contain Chinese characters or spaces
git clone https://github.com/Ha0Liu/CVE-2022-22947.git

Open the downloaded code package with IDEA: Open ---> Path of downloaded file ---> Open.
Create a project manually and set up the environment.
(1) Create a new project, configure it and click Next all the way through;

(2) Analyze the project directory structure:
.idea folder contains IntelliJ IDEA default configuration files with no other use; can be deleted or retained as needed.src folder is the main code area for the entire project, which includes two subfolders: java and resources. java is the area for writing Java code in the project, and resources is the configuration area for the entire project. By default, Spring projects add the SpringApplication method in java, which is the default startup method for Spring. The resources folder contains application.properties by default, which is the configuration file for the Spring project.test folder is for testing; test methods can be placed here.pom.xml is the Maven configuration file, including dependencies, configurations, etc. needed for the project..iml file is the Maven dependency package configuration, also added by default.External Libraries folder contains all dependency packages for the project.
(3) Add Maven dependencies to the pom.xml file (the Maven Repository contains details of all dependencies).
pom file, details as follows:
spring-boot-starter dependency as the server starter. Furthermore, because this vulnerability is in the Gateway of SpringCloud, the vulnerable version is below 3.1.1. Therefore, we use version 3.1.0 for reproduction. Also, we need to monitor and access the gateway through the actuator interface, so we also need this dependency. The specific contents are as follows:
(4) Modify the Spring configuration file (path: src → main → resources → application.properties), details as follows:
server.port is the startup port of the Spring server, default is 8080. You can set it according to your needs.management.endpoint.gateway.enabled=true enables the actuator endpoint to detect the SpringCloud-Gateway gateway. The default is false. Since this vulnerability requires monitoring the state of the gateway, we need to manually change it to true to enable monitoring.management.endpoints.web.exposure.include=gateway selects the server gateway as the Gateway gateway. Since this vulnerability is a Gateway gateway vulnerability, we declare in the configuration file to select the Gateway gateway.
(5) Modify the automatically generated Java class after creating the new project (class name is usually ProjectName + Application, path: src → main → java → com.xxx.xxx → xxxApplication). See the figure below for details:

(6) Start the project, as shown below:

(7) Access http://localhost:9000. If the page is consistent with the screenshot, the environment setup is successful.

(1) First, let's look at the official fix patch, diff as follows: https://github.com/spring-cloud/spring-cloud-gateway/commit/337cef276bfd8c59fb421bfe7377a9e19c68fe1e . In the function org.springframework.cloud.gateway.support.ShortcutConfigurable#getValue, the official replaced StandardEvaluationContext with GatewayEvaluationContext to execute SPEL expressions.

From the figure above, we can see that this patch mainly modifies the parsing method of SPEL expressions. Line 66 shows an if statement indicating that the SPEL expression must start with #{ and end with }. The getValue method performs SPEL expression parsing, indicating that this vulnerability is an RCE vulnerability triggered by SPEL expressions.
(2) Click on the getValue field while holding Ctrl (or Control + left mouse click) to backtrack and find the enumeration org.springframework.cloud.gateway.support.ShortcutConfigurable.ShortcutType.

From the default method above, we can see that the DEFAULT method in the enumeration is called. The method details are as follows:
default ShortcutType shortcutType() {
return ShortcutType.DEFAULT;
}

(3) Backtrack further to find org.springframework.cloud.gateway.support.ConfigurationService.class#normalizeProperties().

This normalizeProperties() method parses the properties of the filter, passing the filter's configuration properties into normalize, and finally enters getValue to execute the SPEL expression, causing SPEL injection.
(1) According to the documentation [https://cloud.spring.io/spring-cloud-gateway/multi/multi__actuator_api.html](https://cloud.spring.io/spring-cloud-gateway/multi/multi actuator_api.html ), users can create and delete routes in the gateway via actuator. The figure below shows the basic structure of the gateway.

(2) In IDEA, you can use the actuator's mapping feature to find the functional interfaces for gateway creation, deletion, etc.

(3) Trace to the RouteDefinition class, which declares the structure of the gateway.
