LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-22963: VMware Tanzu Spring Cloud Function Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Aug 25, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Sep 15, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-22963 to its Known Exploited Vulnerabilities catalog on Aug 25, 2022, with a federal patch deadline of Sep 15, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

When using routing functionality in VMware Tanzu's Spring Cloud Function, it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution…

CVE-2022-22963 is a remote code execution vulnerability in VMware Tanzu Spring Cloud Function. When routing functionality is in use, an attacker can supply a specially crafted Spring Expression Language (SpEL) value as a routing-expression, which may allow execution of code and access to local resources on the affected system.

This matters because Spring Cloud Function is often used in cloud-native and microservice environments where untrusted input can reach routing logic. Successful abuse can give an attacker a foothold on the host or container running the function runtime. Confirm exact affected products and fixed releases against the vendor advisory.

How it works

The weakness is classified as CWE-94 (Improper Control of Generation of Code / Code Injection). In products that evaluate expression languages such as SpEL for routing decisions, user-controlled input that is not strictly constrained can be interpreted as executable expression content rather than as inert data.

According to the CISA summary, when routing functionality in VMware Tanzu Spring Cloud Function is enabled, a user can provide a specially crafted SpEL routing-expression. That expression may be evaluated in a way that results in remote code execution and access to local resources. Public detail on exact request shape, headers, or payloads is limited here; treat any untrusted input that influences routing-expression evaluation as in scope and verify behavior against the vendor advisory and your own testing in a lab.

Am I affected? How to find it in your systems

VMware Tanzu Spring Cloud Function typically appears in Java-based microservice, serverless-style, or event-driven applications—often as a library or runtime component inside application servers, containers, or platform-as-a-service deployments that use Spring Cloud.

How to remediate

Patch first. Apply updates per vendor instructions, as required by CISA for this CVE. Replace vulnerable Spring Cloud Function components with the fixed builds named in the VMware Tanzu advisory and redeploy affected services.

If you can't patch immediately

Compensate until you can apply the vendor update:

If your data may have been exposed

Actively exploited remote code execution flaws can lead to host compromise and data access; ransomware use is not documented for this CVE in the given facts. If you suspect exploitation, follow your incident response process: isolate affected workloads, preserve logs, rotate credentials that may have been reachable from the runtime, and assess what local resources the function identity could access. You can also run a free exposure scan of your email addresses against known breach data to see whether associated accounts appear in prior breaches while you complete containment and recovery.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedVMware Tanzu · Spring Cloud
WeaknessCWE-94
Added to CISA KEVAug 25, 2022
Federal patch deadlineSep 15, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities