CVE-2022-22963

critical

Description

In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.

References

https://github.com/yt010108/CVEs

https://github.com/lr-elaina520/cve-analysis

https://github.com/berinle/spring-enterprise-remediation-demo

https://github.com/heyjerrybecker/seevie-pri

https://github.com/wyqsgy/vulnark

https://github.com/psyf8t/spring-security-rules

https://github.com/teofoli-matteo/CVE-2022-22963---Software-Vulnerabilities

https://github.com/C4yberLan/SpringBoot-Exploit-Toolkit

https://github.com/Karararam/SpringBoot-Exploit-Toolkit

https://github.com/g1san/Agents-for-Vulnerable-Dockers-and-related-Benchmarks

https://github.com/minchan02/CVE-Manage

https://github.com/charonlight/SpringExploitGUI

https://github.com/xmqaq/CVE-2022-22963

https://github.com/JorgeRh4ck/CVE-Exploits

https://github.com/HenriVlasic/Exploit-for-CVE-2022-22963

https://github.com/gunzf0x/CVE-2022-22963

https://github.com/GunZF0x/CVE-2022-22963

https://github.com/SourM1lk/CVE-2022-22963-Exploit

https://github.com/J0ey17/CVE-2022-22963_Reverse-Shell-Exploit

https://github.com/StarCrossPortal/VulnsDB

https://github.com/tpt11fb/SpringVulScan

https://github.com/k3rwin/spring-cloud-function-rce

https://github.com/wyunan/CVE-Details

https://github.com/SealPaPaPa/SpringCloudFunction-Research

https://github.com/advisories/GHSA-6v73-fgf6-w5j7

https://github.com/mebibite/springhound

https://github.com/stevemats/Spring0DayCoreExploit

https://github.com/TheGejr/SpringShell

https://github.com/RanDengShiFu/CVE-2022-22963

https://github.com/XuCcc/VulEnv

https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-22963

https://tanzu.vmware.com/security/cve-2022-22963

http://packetstormsecurity.com/files/173430/Spring-Cloud-3.2.2-Remote-Command-Execution.html

Details

Source: Mitre, NVD

Published: 2022-04-01

Updated: 2026-06-17

Known Exploited Vulnerability (KEV)

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.99939