Cybersecurity Alerts

Actively Exploited Vulnerabilities

← Back to Cybersecurity Alerts

CVE-2022-22963

VMware Tanzu | Spring CloudAdded 2022-08-25Remediation Deadline 2022-09-15

VMware Tanzu Spring Cloud Function Remote Code Execution Vulnerability

When using routing functionality in VMware Tanzu's Spring Cloud Function, it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.

Required Action

Apply updates per vendor instructions.

Weakness Classification

CWE-94

References