
Spring Cloud Gateway Actuator API SpEL式インジェクションによるコマンド実行(CVE-2022-22947) Godzillaメモリシェルの注入
Spring Cloud Gateway Actuator API SpEL式インジェクションによるコマンド実行(CVE-2022-22947) Godzillaメモリシェルを注入
デフォルトキー pass base64
注:コードはルート部分をクリアしていないので、自分でクリアしてください。。
テスト環境:https://github.com/vulhub/vulhub/blob/master/spring/CVE-2022-22947/README.zh-cn.md
メモリシェルclass https://github.com/whwlsfb/cve-2022-22947-godzilla-memshell