
Spring Cloud Gateway SpEL RCE Vulnerability Environment
Spring Cloud Gateway has a SpEL expression injection vulnerability. When the Actuator endpoint is enabled, an attacker can achieve remote code execution (RCE).
docker-compose up -d
http://your-ip:8080/actuator/gateway/routes