In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "3.1.6"
},
{
"introduced": "3.2.0"
},
{
"last_affected": "3.2.2"
}
]
}"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-22963.json"
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "14.5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "14.5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "14.5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "14.5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "14.5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "14.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "14.5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "14.5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "14.5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "14.5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "14.5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.9.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "22.1.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.9.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "22.1.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "22.1.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.10.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "22.1.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "22.1.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.15.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "22.1.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "22.1.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.15.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "22.1.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "22.1.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.7.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "22.1.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.15.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "22.1.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12.6.0.0.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.1.1.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.1.2.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.1.1.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.1.1.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.1.2.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.1.1.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.1.1.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.1.2.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0.29"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "3.6.1.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "20.0.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "21.0.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.1"
}
]
}
]