S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-22053 Scanner

CVE-2021-22053 scanner - Remote Code Execution (RCE) vulnerability in Spring Cloud Netflix

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.4k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-22053
8.8
CVSS

Applications using both `spring-cloud-netflix-hystrix-dashboard` and `spring-boot-starter-thymeleaf` expose a way to execute code submitted within the request URI path during the resolution of view templates. When a request is made at `/hystrix/monitor;[user-provided data]`, the path elements following `hystrix/monitor` are being evaluated as SpringEL expressions, which can lead to code execution.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Spring Cloud Netflixby n/a
Spring Cloud Netflix versions 2.2.x prior to 2.2.10.Release + and old unsupported versions
Updated Aug 21, 2026View on NVD →
Detail

Spring Cloud Netflix is a set of tools that makes it easier to develop microservices that are cloud-native. It provides a range of useful features such as service discovery, load balancing, and circuit breaking. One of the key tools in the Spring Cloud Netflix suite is the Hystrix Dashboard, which provides a real-time view of your application's metrics. This can be invaluable in understanding how your application is performing and identifying any issues that need to be addressed.

The CVE-2021-22053 vulnerability is a critical security flaw that has been detected in the Spring Cloud Netflix Hystrix Dashboard. It is related to the way that user-provided data is evaluated as Spring Expression Language (SpEL) expressions in the view templates. An attacker could exploit this vulnerability by submitting crafted data in the URI path, leading to remote code execution on the server.

If this vulnerability is exploited, it can lead to disastrous consequences for your application. Depending on the attacker's intentions, they could potentially steal sensitive data, install malware, or even take control of the server. It is critical that this vulnerability is patched as soon as possible to avoid any such attacks.

Thanks to the pro features of the s4e.io platform, those who read this article can easily and quickly learn about vulnerabilities in their digital assets. Our platform provides real-time threat intelligence and alerts when vulnerabilities are discovered, allowing you to take immediate action to protect your applications from attack. With s4e.io, you can rest easy knowing that your digital assets are always secure.

 

REFERENCES

Solution Advice

To protect against this vulnerability, it is recommended that you take the following precautions:

  • Upgrade to the latest version of Spring Cloud Netflix Hystrix Dashboard, which contains a fix for this vulnerability.
  • Implement strict input validation to prevent crafted input from being submitted in the URI path.
  • Monitor your application for any suspicious activity and investigate any unusual traffic patterns.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-22053 scanner - Remote Code Execution (RCE) vulnerability in Spring Cloud Netflix S4E