Skip to content
KitploitKITPLOIT
ツールブログ
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
CVE-2022-22947 — CVE-2022-22947 エクスプロイトスクリプト | Kitploit
ツール/GitHubGitHub/cc3305/cve-2022-22947
脆弱性分析コード分析エクスプロイトウェブアプリケーション悪用ペネトレーションテスト
GitHubcc3305/cve-2022-22947

CVE-2022-22947

CVE-2022-22947 エクスプロイトスクリプト

リポジトリを見る
2年前未レビュー

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有

CVE-2022-22947

Spring Cloud Gateway へのコードインジェクション攻撃

CVE の概要

Spring Cloud Gateway のバージョン 3.1.1+ および 3.0.7+ より前のバージョンでは、Gateway Actuator エンドポイントが有効、公開、かつ保護されていない場合、アプリケーションはコードインジェクション攻撃に対して脆弱です。リモートの攻撃者は悪意を持って細工されたリクエストを行うことで、リモートホスト上で任意のリモート実行を可能にする可能性があります。

影響を受けるバージョン

  • Oracle Commerce Guided Search 11.3.2
  • Oracle Communications Cloud Native Core Network Function Cloud Native Environment 1.10.0
  • Oracle Communications Cloud Native Core Console 22.2.0
  • Oracle Communications Cloud Native Core Network Slice Selection Function 1.8.0
  • Oracle Communications Cloud Native Core Network Slice Selection Function 22.1.0
  • Oracle Communications Cloud Native Core Security Edge Protection Proxy 22.1.1
  • Oracle Communications Cloud Native Core Network Repository Function 1.15.0
  • Oracle Communications Cloud Native Core Network Repository Function 1.15.1
  • Oracle Communications Cloud Native Core Network Repository Function 22.2.0
  • Oracle Communications Cloud Native Core Network Repository Function 22.1.2
  • Oracle Communications Cloud Native Core Binding Support Function 1.11.0
  • Oracle Communications Cloud Native Core Binding Support Function 22.1.3
  • Oracle Communications Cloud Native Core Service Communication Proxy 1.15.0
  • Oracle Communications Cloud Native Core Network Exposure Function 22.1.0
  • Vmware Spring Cloud Gateway < 3.0.7
  • Vmware Spring Cloud Gateway 3.1.0

参考文献

  • Github POC - luckone, Mar 02 2022
  • Spring Security Advisories, Mar 01 2022
  • Original Discovery - Wyatt Dahlenburg, Feb 26 2022
  • CVE-details - CVSS Score 10.0
ツールをダウンロード