CVE-2022-22947
Um ataque de injeção de código no spring cloud gateway
Resumo do CVE
Nas versões do spring cloud gateway anteriores a 3.1.1+ e 3.0.7+, as aplicações são vulneráveis a um ataque de injeção de código quando o endpoint do Gateway Actuator está ativado, exposto e não seguro. Um atacante remoto pode fazer uma requisição maliciosamente elaborada que poderia permitir execução remota arbitrária no host remoto.
Versões Afetadas
- Oracle Commerce Guided Search 11.3.2
- Oracle Communications Cloud Native Core Network Function Cloud Native Environment 1.10.0
- Oracle Communications Cloud Native Core Console 22.2.0
- Oracle Communications Cloud Native Core Network Slice Selection Function 1.8.0
- Oracle Communications Cloud Native Core Network Slice Selection Function 22.1.0
- Oracle Communications Cloud Native Core Security Edge Protection Proxy 22.1.1
- Oracle Communications Cloud Native Core Network Repository Function 1.15.0
- Oracle Communications Cloud Native Core Network Repository Function 1.15.1
- Oracle Communications Cloud Native Core Network Repository Function 22.2.0
- Oracle Communications Cloud Native Core Network Repository Function 22.1.2
- Oracle Communications Cloud Native Core Binding Support Function 1.11.0
- Oracle Communications Cloud Native Core Binding Support Function 22.1.3
- Oracle Communications Cloud Native Core Service Communication Proxy 1.15.0
- Oracle Communications Cloud Native Core Network Exposure Function 22.1.0
- Vmware Spring Cloud Gateway < 3.0.7
- Vmware Spring Cloud Gateway 3.1.0
Referências