S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-22963 Scanner

CVE-2022-22963 scanner - Remote Code Execution (RCE) vulnerability in Spring Cloud Function

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.1k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2022-22963
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Spring Cloud Functionby n/a
Spring Cloud Function versions 3.1.6, 3.2.2 and all old and unsupported versions
Updated Aug 22, 2026View on NVD →
Detail

Spring Cloud Function is a framework that provides developers with the ability to write serverless functions in a variety of programming languages, including Java. These functions can be run on any platform that supports the Spring framework, including Google Cloud Platform and Amazon Web Services. Spring Cloud Function enables developers to write code that is focused on solving business problems, making development simpler and more efficient.

The CVE-2022-22963 vulnerability that has been detected in Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions occurs when using routing functionality. This vulnerability enables users to provide a specially crafted SpEL as a routing-expression, which can result in remote code execution and access to local resources. This means that an attacker who exploits this vulnerability can gain access to sensitive data or carry out unauthorized actions on the affected system.

Exploiting this vulnerability can lead to severe consequences for an organization. An attacker could potentially take control of the affected system, gain access to sensitive data, or launch further attacks against other systems on the network. In addition, they could use the vulnerability to carry out other malicious activities, like stealing information, encrypting data and demanding a ransom, or disrupting critical business operations.

Thanks to the pro features of the s4e.io platform, those who read this article can easily and quickly learn about vulnerabilities in their digital assets. By using our platform, you can receive real-time notifications about newly discovered vulnerabilities and get immediate access to in-depth reports, solutions, and recommendations to help you protect your digital assets. You can also use our platform to scan your applications or infrastructure for vulnerabilities and receive detailed risk profiles and remediation guidance. With s4e.io, you can be confident in your ability to protect your digital assets from threats.

 

REFERENCES

Solution Advice

To protect against this vulnerability, we recommend the following precautions:

  • Upgrade to the latest supported version of Spring Cloud Function.
  • Review and monitor routing expressions used in the application.
  • Ensure that the application is behind a secure network perimeter, such as a firewall.
  • Use strong authentication and authorization mechanisms.
  • Monitor network traffic for unusual activity and investigate any suspicious activity.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-22963 scanner - Remote Code Execution (RCE) vulnerability in Spring Cloud Function | S4E