Maven package intelligence
org.springframework.cloud:spring-cloud-gateway Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting the Maven package org.springframework.cloud:spring-cloud-gateway, including the gap beyond CISA KEV, confidence assessments, and sensor observations.
- Total KEVs
- 1
- Known exploited vulnerability affecting org.springframework.cloud:spring-cloud-gateway
- In CISA KEV
- 1
- Records also listed in the official catalog
- Beyond CISA KEV
- 0
- Additional exploited vulnerabilities absent from CISA KEV
- Sensor Observed
- 0
- org.springframework.cloud:spring-cloud-gateway KEVs with sensor-observed exploitation activity
Review org.springframework.cloud:spring-cloud-gateway exploitation against the versions you run
All one exploited org.springframework.cloud:spring-cloud-gateway vulnerability tracked here is also listed in CISA KEV.
- 100%
- Covered by CISA
- 0%
- Beyond CISA
Attested org.springframework.cloud:spring-cloud-gateway vulnerabilities
1 known exploited vulnerability affecting this package.
| Vulnerability | CISA KEV | Added |
|---|---|---|
|
CVE-2022-22947
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator... |
In CISA | 16 May 2022 |
Recurring weakness patterns
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') and Improper Control of Generation of Code ('Code Injection') account for mapped occurrences across this org.springframework.cloud:spring-cloud-gateway KEV portfolio.