CVE-2022-22947
VMware Spring Cloud Gateway Code Injection Vulnerability
- 대응 우선순위
- 최우선
- CVSS
- 10
- EPSS
- 98.3% 백분위 99.9% · 2026.06.27 기준
- CISA KEV
- 등록
- 조치 기한
- 2022.06.06
- 공개일
- 2022.03.04
CISA KEV에 등록된 실제 악용 확인 취약점
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote execution on the remote host.
공급사 VMware
제품 Spring Cloud Gateway
영향 버전 Spring cloud gateway versions 3.1.x prior to 3.1.1+, 3.0.x prior to 3.0.7+ and all old and unsupported versions, < 3.0.7, 3.1.0, 11.3.2, 1.11.0, 22.1.3, 22.2.0, 22.1.0, 1.10.0, 1.15.0, 1.15.1, 22.1.2, 1.8.0, 22.1.1
수정 버전 3.0.7
Apply updates per vendor instructions.
조치 기한: 2022.06.06CVSS 벡터 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE CWE-917, CWE-94
KEV 등록일 2022.05.16
랜섬웨어 캠페인 사용 미확인
CISA 비고 https://nvd.nist.gov/vuln/detail/CVE-2022-22947
EPSS 데이터 기준일 2026.06.27