UNKNOWNKNOWN EXPLOITED
CVE-2022-22947
VMware Spring Cloud Gateway Code Injection Vulnerability
Summary
Spring Cloud Gateway applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured.
References
Includes data from the CISA Known Exploited Vulnerabilities catalog.
CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.