CVE-2022-22947
Атака внедрения кода на spring cloud gateway
Обзор CVE
В версиях spring cloud gateway до 3.1.1+ и 3.0.7+ приложения уязвимы для атаки внедрения кода, когда конечная точка Gateway Actuator включена, доступна и не защищена. Удаленный злоумышленник может отправить специально сформированный запрос, который может позволить произвольное удаленное выполнение на удаленном хосте.
Затронутые версии
- Oracle Commerce Guided Search 11.3.2
- Oracle Communications Cloud Native Core Network Function Cloud Native Environment 1.10.0
- Oracle Communications Cloud Native Core Console 22.2.0
- Oracle Communications Cloud Native Core Network Slice Selection Function 1.8.0
- Oracle Communications Cloud Native Core Network Slice Selection Function 22.1.0
- Oracle Communications Cloud Native Core Security Edge Protection Proxy 22.1.1
- Oracle Communications Cloud Native Core Network Repository Function 1.15.0
- Oracle Communications Cloud Native Core Network Repository Function 1.15.1
- Oracle Communications Cloud Native Core Network Repository Function 22.2.0
- Oracle Communications Cloud Native Core Network Repository Function 22.1.2
- Oracle Communications Cloud Native Core Binding Support Function 1.11.0
- Oracle Communications Cloud Native Core Binding Support Function 22.1.3
- Oracle Communications Cloud Native Core Service Communication Proxy 1.15.0
- Oracle Communications Cloud Native Core Network Exposure Function 22.1.0
- Vmware Spring Cloud Gateway < 3.0.7
- Vmware Spring Cloud Gateway 3.1.0
Ссылки