VMware Spring Cloud Gateway是美国威睿(VMware)公司的提供了一个用于在 Spring WebFlux 之上构建 API 网关的库。 VMware Spring Cloud Gateway 存在代码注入漏洞,远程攻击者可利用该漏洞发出恶意的请求并允许在远程主机上执行任意远程命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | Spring Cloud Gateway | Spring cloud gateway versions 3.1.x prior to 3.1.1+, 3.0.x prior to 3.0.7+ and all old and unsupported versions | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | CVE-2022-22947 | https://github.com/lucksec/Spring-Cloud-Gateway-CVE-2022-22947 | POC Details |
| 2 | poc for cve-2022-22947 | https://github.com/scopion/cve-2022-22947 | POC Details |
| 3 | Spring cloud gateway code injection : CVE-2022-22947 | https://github.com/Vulnmachines/spring-cve-2022-22947 | POC Details |
| 4 | Spring Cloud Gateway 远程代码执行漏洞Exp Spring_Cloud_Gateway_RCE_Exp-CVE-2022-22947 | https://github.com/Axx8/CVE-2022-22947_Rce_Exp | POC Details |
| 5 | Spring Cloud Gateway < 3.0.7 & < 3.1.1 Code Injection (RCE) | https://github.com/crowsec-edtech/CVE-2022-22947 | POC Details |
| 6 | SpringCloudGatewayRCE - CVE-2022-22947 / Code By:Tas9er | https://github.com/Tas9er/SpringCloudGatewayRCE | POC Details |
| 7 | None | https://github.com/Greetdawn/CVE-2022-22947 | POC Details |
| 8 | Spring Cloud Gateway远程代码执行漏洞 | https://github.com/Summer177/Spring-Cloud-Gateway-CVE-2022-22947 | POC Details |
| 9 | Exp | https://github.com/BerMalBerIst/CVE-2022-22947 | POC Details |
| 10 | CVE-2021-42013批量 | https://github.com/tangxiaofeng7/CVE-2022-22947-Spring-Cloud-Gateway | POC Details |
| 11 | cve-2022-22947 spring cloud gateway 批量扫描脚本 | https://github.com/dingxiao77/-cve-2022-22947- | POC Details |
| 12 | 日常更新一些顺手写的gobypoc,包含高危害EXP | https://github.com/flying0er/CVE-2022-22947-goby | POC Details |
| 13 | Spring Cloud Gateway Actuator API 远程命令执行 CVE-2022-22947 | https://github.com/dbgee/CVE-2022-22947 | POC Details |
| 14 | Spring-Cloud-Gateway-CVE-2022-22947 | https://github.com/nu0l/cve-2022-22947 | POC Details |
| 15 | CVE-2022-22947批量检测脚本,回显命令没进行正则,大佬们先用着,后续再更 | https://github.com/nanaao/CVE-2022-22947-POC | POC Details |
| 16 | 批量url检测Spring-Cloud-Gateway-CVE-2022-22947 | https://github.com/hunzi0/CVE-2022-22947-Rce_POC | POC Details |
| 17 | None | https://github.com/22ke/CVE-2022-22947 | POC Details |
| 18 | Spring Cloud Gateway远程代码执行漏洞POC,基于命令执行的基础上,增加了反弹shell操作 | https://github.com/M0ge/CVE-2022-22947-Spring-Cloud-Gateway-SpelRCE | POC Details |
| 19 | Spring Cloud Gateway Actuator API SpEL表达式注入命令执行(CVE-2022-22947)批量检测工具 | https://github.com/YutuSec/SpEL | POC Details |
| 20 | SpringCloudGatewayRCE / Code By:Jun_sheng | https://github.com/Jun-5heng/CVE-2022-22947 | POC Details |
| 21 | None | https://github.com/darkb1rd/cve-2022-22947 | POC Details |
| 22 | Spring Cloud Gateway Actuator API SpEL Code Injection (CVE-2022-22947) | https://github.com/mrknow001/CVE-2022-22947 | POC Details |
| 23 | CVE-2022-22947_EXP,CVE-2022-22947_RCE,CVE-2022-22947反弹shell,CVE-2022-22947 getshell | https://github.com/aodsec/CVE-2022-22947 | POC Details |
| 24 | 调试代码包含断点信息,直接导入即可进行调试 | https://github.com/ba1ma0/Spring-Cloud-GateWay-CVE-2022-22947-demon-code | POC Details |
| 25 | CVE-2022-22947 Exploit script | https://github.com/Arrnitage/CVE-2022-22947_exp | POC Details |
| 26 | None | https://github.com/PaoPaoLong-lab/Spring-CVE-2022-22947- | POC Details |
| 27 | cve-2022-22947-docker | https://github.com/hh-hunter/cve-2022-22947-docker | POC Details |
| 28 | spring-cloud-gateway-rce CVE-2022-22947 | https://github.com/k3rwin/spring-cloud-gateway-rce | POC Details |
| 29 | None | https://github.com/bysinks/CVE-2022-22947 | POC Details |
| 30 | CVE-2022-22947_POC_EXP | https://github.com/Wrin9/CVE-2022-22947 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2021-45819 | 6.4 MEDIUM | Wordline HIDCCEMonitorSVC 代码问题漏洞 |
| CVE-2021-3609 | Linux kernel 竞争条件问题漏洞 | |
| CVE-2022-26127 | FRRouting FRR 缓冲区错误漏洞 | |
| CVE-2022-26128 | FRRouting FRR 缓冲区错误漏洞 | |
| CVE-2022-26129 | FRRouting FRR 缓冲区错误漏洞 | |
| CVE-2022-23898 | MingSoft Mcms SQL注入漏洞 | |
| CVE-2022-23899 | MingSoft Mcms SQL注入漏洞 | |
| CVE-2022-25125 | MingSoft Mcms SQL注入漏洞 | |
| CVE-2022-22700 | CyberArk Identity 安全特征问题漏洞 | |
| CVE-2021-3620 | Red Hat Ansible 安全漏洞 | |
| CVE-2022-25138 | Axelor Open Suite 跨站脚本漏洞 | |
| CVE-2021-3602 | Buildah 信息泄露漏洞 | |
| CVE-2021-3762 | Clair 路径遍历漏洞 | |
| CVE-2021-4002 | Linux kernel 安全漏洞 | |
| CVE-2022-23051 | PeTeReport 跨站脚本漏洞 | |
| CVE-2022-23052 | PeTeReport 跨站请求伪造漏洞 | |
| CVE-2022-25220 | PeTeReport 跨站脚本漏洞 | |
| CVE-2022-22943 | VMware Tools for Windows 代码问题漏洞 | |
| CVE-2021-3640 | Linux kernel 资源管理错误漏洞 | |
| CVE-2022-23849 | Devolutions Password Hub 授权问题漏洞 |
Showing top 20 of 37 CVEs. View all on vendor page → →
No comments yet