claytonvantol.us
SESSION: secure TLS: 1.3 PID: 1337

clayton@site:~/news$ cat cve-2022-22963-vmware-tanzu-spring-cloud.log

CVE-2022-22963 — VMware Tanzu Spring Cloud Function Remote Code Execution Vulnerability

2022-08-25 • CISA Known Exploited Vulnerability


[event] When using routing functionality in VMware Tanzu's Spring Cloud Function, it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.

> AFFECTED SOFTWARE

Field Value
Vendor VMware Tanzu
Product Spring Cloud
CWE CWE-94
CVE ID CVE-2022-22963
Date Added 2022-08-25
Due Date 2022-09-15
Ransomware Campaign Unknown

> MITIGATION

Apply updates per vendor instructions.

Due Date: 2022-09-15

> REFERENCES


← back to terminal

UPTIME: 1337d v2.0.1 privacy LAST LOGIN: 2026-05-30 20:36:11 UTC