CISA Known Exploited Vulnerability
This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.
Remediation Deadline: Jun 6, 2022
High
CISA KEVCVE-2022-22947
VMware—Spring Cloud Gateway
Spring Cloud Gateway applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured.
Required Action
https://nvd.nist.gov/vuln/detail/CVE-2022-22947
Vulnerability Overview
- Severity
- High
- CISA KEV
- Yes
- Ransomware
- Unknown
- Published
- May 16, 2022
- KEV Added
- May 16, 2022
- Due Date
- Jun 6, 2022
- Related Articles
- 0
Vendor
VMware
Spring Cloud Gateway