Vulnerability record · CVE-2022-22947 · published 3 March 2022
CVE-2022-22947: Spring Cloud Gateway Actuator endpoint code injection
Vmware · Spring Cloud Gateway
Spring Cloud Gateway versions before 3.1.1+ and 3.0.7+ allow code injection when the Gateway Actuator endpoint is enabled, exposed and unsecured. A crafted request can trigger expression language evaluation leading to arbitrary remote code execution. The flaw matters because it is network reachable, needs no authentication or user interaction, and has a maximum CVSS score of 10.0.
Description
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote execution on the remote host.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable remote code execution with CVSS 10.0, KEV listing and near-maximum EPSS makes this an urgent patch-first item.
What it is
Spring Cloud Gateway versions before 3.1.1+ and 3.0.7+ allow code injection when the Gateway Actuator endpoint is enabled, exposed and unsecured. A crafted request can trigger expression language evaluation leading to arbitrary remote code execution. The flaw matters because it is network reachable, needs no authentication or user interaction, and has a maximum CVSS score of 10.0.
Impact
An unauthenticated remote attacker can execute arbitrary code on the host running the gateway, giving full control of that process and its data. Because the CVSS scope is changed, compromise can extend beyond the gateway component itself.
Attack surface
Reached over the network via HTTP requests to the exposed Gateway Actuator endpoint; the vector shows no privileges and no user interaction required. Exposure depends on the Actuator endpoint being enabled, exposed and left unsecured.
Exploitation
Listed in CISA KEV since 2022-05-16 with a required action to apply vendor updates, and public exploit references exist. EPSS is 0.98253 (99.9th percentile), indicating very high likelihood of exploitation activity.
What to do
- Upgrade Spring Cloud Gateway to 3.1.1+ or 3.0.7+ (or later) per the VMware advisory, and apply the referenced Oracle CPU patches for affected Oracle products.
- Disable the Gateway Actuator endpoint where it is not operationally required.
- If the Actuator must run, restrict it to trusted management networks and require authentication; never expose it to the internet.
- Audit gateway configuration and network exposure for unsecured Actuator routes, and remove any unnecessary management endpoints.
- Monitor vendor advisories for updated fixed versions and re-check affected deployments.
Detection
- Inspect gateway and reverse proxy logs for requests to Actuator routes, especially POST/PUT/DELETE to /actuator/gateway/routes and refresh endpoints.
- Alert on unexpected outbound connections or child processes spawned by the gateway Java process.
- Search for route definitions or Actuator responses containing expression language syntax such as SpEL or ${...} patterns.
- Review gateway configuration changes and new route registrations for unauthorized additions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-22947 to the Known Exploited Vulnerabilities catalog on 16 May 2022 as "VMware Spring Cloud Gateway Code Injection Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 6 June 2022.
Affected products
10 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-22947 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-22947), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.