Skip to main content

CVE detail

CVE-2022-22963

In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.

CVSS 9.8 · CriticalBuzz score 77.3KEV listed1 public exploit repository references

Buzz score

Why this CVE is surfacing

Buzz score total 77.3

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 28.9 · diversity 16.0 · KEV 25.0 · OTX 0.0 · PoC 7.5
Mention score
28.9
17 evidence mentions in the snapshot
Diversity score
16.0
6 sources across 2 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
7.5
1 repos · best confidence 0.99
Best PoC traction
355
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
17 source links · newest first
  • The number of fileless or memory-based attacks that exploit existing software, applications, and protocols have surged 1,400% in the last year. That’s according to Aqua Security’s 2023 Cloud Native Threat Report, which summarizes research and observations of threat actors’ changing tactics, techniques, and procedures (TTPs), along with outlining strategies for protecting cloud environments. Based on […]

    newswww.csoonline.comJun 27, 2023, 8:00 AM
  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added 10 new flaws to its Known Exploited Vulnerabilities Catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added 10 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, including a high-severity security flaw (CVE-2021-38406 CVSS score: 7.8) impacting Delta Electronics industrial automation software. According to Binding Operational Directive (BOD) 22-01: […]

    newssecurityaffairs.comAug 29, 2022, 9:03 AM
  • A vulnerability affecting industrial automation software from Delta Electronics appears to have been exploited in attacks, and the US Cybersecurity and Infrastructure Security Agency (CISA) is urging organizations to take action as soon as possible.

    newswww.securityweek.comAug 26, 2022, 10:28 AM
  • Recent exploits observed in the wild are highlighted based on the availability of proofs of concept, the severity of the vulnerabilities the exploits are based on and the ease of exploitation.

    vendorunit42.paloaltonetworks.comAug 19, 2022, 11:00 PM
  • The 2022 Unit 42 Network Threat Trends Research Report includes an analysis of the CVEs most commonly exploited in 2021 and predictions for which CVEs attackers will likely focus on in the year to come.

    vendorunit42.paloaltonetworks.comJul 21, 2022, 1:00 PM
  • Oracle on Tuesday announced the release of 520 security fixes as part of its April 2022 Critical Patch Update (CPU), including nearly 300 for vulnerabilities that can be exploited remotely without authentication.

    newswww.securityweek.comApr 20, 2022, 9:57 AM
  • When a significant vulnerability like Spring4Shell is discovered, how do you determine if you are at risk? Insurance or verification services might require you to run external tests on web properties. These reports often show spurious exposures that may or may not lead to more issues on your website. You must research false-positive reports and […]

    newswww.csoonline.comApr 20, 2022, 9:00 AM
  • Cybersecurity firm Trend Micro on Friday confirmed some earlier reports that the new Spring4Shell vulnerability has been exploited by the Mirai botnet. Two critical vulnerabilities have been patched recently in the popular Java application development framework Spring: CVE-2022-22965 (aka Spring4Shell and SpringShell) and CVE-2022-22963.

    newswww.securityweek.comApr 8, 2022, 12:51 PM
  • US Government Agencies Instructed to Patch Spring4Shell Vulnerability Enterprise defenders have been provided information and tools to help them deal with Spring4Shell and potential attacks exploiting the vulnerability.

    newswww.securityweek.comApr 5, 2022, 12:47 PM
  • Companies are assessing the impact of the Spring vulnerability dubbed Spring4Shell on their products, and while some vendors have started releasing patches, many have determined that their products do not appear to be affected.

    newswww.securityweek.comApr 4, 2022, 10:41 AM
  • The Spring zero-day vulnerability named Spring4Shell (SpringShell) has been patched, just as several cybersecurity firms have confirmed seeing exploitation attempts.

    newswww.securityweek.comApr 1, 2022, 10:11 AM
  • Spring4Shell: New info and fixes (CVE-2022-22965)Help Net Security

    In this video for Help Net Security, Ax Sharma, Senior Security Researcher at Sonatype, talks about the latest developments regarding Spring4Shell, the unauthenticated RCE zero-day vulnerability in Spring Core whose existence has finally been confirmed by its developers. Spring4Shell has been catalogued as CVE-2022-22965 and fixed in Spring Framework 5.3.18 and 5.2.20, and Spring Boot (which depends on the Spring Framework) 2.5.12 and 2.6.6. “The vulnerability impacts Spring MVC and Spring WebFlux applications running on … More →

    newswww.helpnetsecurity.comApr 1, 2022, 6:20 AM
  • CVE-2022-22965, aka SpringShell, is a remote code execution vulnerability in the Spring Framework. We provide a root cause analysis and mitigations.

    vendorunit42.paloaltonetworks.comMar 31, 2022, 11:30 PM
  • A remote code execution vulnerability in Spring Framework has sparked fears that it could have a widespread impact across enterprise environments. Spring is one of the most popular open-source frameworks for developing Java applications. The flaw, which has since been dubbed SpringShell or Spring4Shell, came to light when a Chinese developer released a proof-of-concept (PoC) […]

    newswww.csoonline.comMar 31, 2022, 5:12 PM
  • m.” Praetorian also said the vulnerability is effective since it bypasses a previous patch made nearly 12 years ago for CVE-2010-1622 , a separate code injection vulnerability in the Spring Core Framework. Some members of the security community have been confusing two separate Spring vulnerabilities. This week's Spring4Shell and CVE-2022-22963 are ent

    newswww.itpro.comMar 31, 2022, 12:15 PM
  • The disclosure of several vulnerabilities affecting the widely used Spring Java framework has led to confusion and concerns that organizations may need to deal with a flaw similar to the notorious Log4Shell. VMware-owned Spring has been described as the world’s most popular Java framework. Spring is designed to increase speed and productivity by making Java programming easier. The cybersecurity community started to panic on Wednesday after a Chinese researcher recently made available a proof-of-concept (PoC) exploit for a remote code execution vulnerability affecting the Spring framework’s Core module. The PoC exploit has since been removed, but researchers who have analyzed it have confirmed that it targets what appears to be an unpatched flaw that can be exploited without authentication. A CVSS score of 10 has been assigned to the bug, but there is no CVE identifier. Cybersecurity company Praetorian reported that the zero-day vulnerability, which has been dubbed Spring4Shell and Spr…

    newswww.securityweek.comMar 31, 2022, 10:38 AM
  • Security teams around the world got another shock on Thursday when news of disclosure of a PoC for an unauthenticated RCE zero-day vulnerability in Spring Core, a massively popular framework for building modern Java-based enterprise applications, began circulating online. Thanks to many security researchers, the situation is a bit clearer today and there’s no need to panic just yet: Unlike Log4Shell, this new flaw – with no official CVE and currently nicknamed Spring4Shell – seems … More →

    newswww.helpnetsecurity.comMar 31, 2022, 10:38 AM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

1 repository references · best confidence 0.99 · max 355 stars

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence