CVE-2022-22947
KEVCRITICAL 10.0EPSS 98.3%
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote execution on the remote host.
- CVSS v3.1
- 10.0 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H - CVSS v3.1
- 10.0 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H - CVSS v3.1
- 10.0 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H - CVSS v2.0
- 6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P - EPSS
- 98.25% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2022-05-16
- Nuclei
- critical
- Published
- 2022-03-03
- Updated
- 2025-10-21
Proof-of-concept exploits (83)
- http://packetstormsecurity.com/files/166219/Spring-Cloud-Gateway-3.1.0-Remote-Code-Execut…
- http://packetstormsecurity.com/files/168742/Spring-Cloud-Gateway-3.1.0-Remote-Code-Execut…
- 0730Nophone/CVE-2022-22947-60★ · 2022-05-16
- 0x7eTeam/CVE-2022-2294735★ · 2022-03-08
- 0x801453/SpringbootGuiExploit20★ · 2024-06-07
- 22ke/CVE-2022-229472★ · 2022-03-05
- 24-2021/EXP-POC26★ · 2023-01-11
- 4nNns/CVE-2022-2294712★ · 2022-09-16
- An0th3r/CVE-2022-22947-exp5★ · 2026-08-12
- Arrnitage/CVE-2022-22947-exp5★ · 2026-08-12
- Arrnitage/CVE-2022-22947_exp5★ · 2026-08-12
- Axx8/CVE-2022-22947_Rce_Exp77★ · 2022-11-14
- BBD-YZZ/GUI-TOOLS25★ · 2024-05-28
- BerMalBerIst/CVE-2022-229470★ · 2022-03-04
- Ciyfly/mullet32★ · 2022-04-27
- Enokiy/cve-2022-22947-spring-cloud-gateway18★ · 2022-04-07
- Greetdawn/CVE-2022-229475★ · 2022-03-04
- Ha0Liu/CVE-2022-2294712★ · 2022-09-16
- Jun-5heng/CVE-2022-229471★ · 2022-03-29
- LY613313/CVE-2022-229473★ · 2022-08-03
- Le1a/CVE-2022-229472★ · 2023-05-27
- M0ge/CVE-2022-22947-Spring-Cloud-Gateway-SpelRCE14★ · 2022-03-09
- MInggongK/SpringbootGuiExploit20★ · 2024-06-07
- Nathaniel1025/CVE-2022-229471★ · 2022-03-25
- Sec-Fork/mullet20★ · 2023-07-18
- SecNN/CVE-2022-22947_Rce_Exp77★ · 2022-11-14
- SiJiDo/CVE-2022-229479★ · 2022-08-23
- Sumitpathania03/CVE-2022-229470★ · 2024-04-02
- Summer177/Spring-Cloud-Gateway-CVE-2022-229470★ · 2022-03-04
- Vancomycin-g/CVE-2022-229472★ · 2022-03-30
- Vulnmachines/spring-cve-2022-2294710★ · 2022-03-03
- Wrin9/CVE-2022-2294711★ · 2022-03-17
- Wrong-pixel/CVE-2022-22947-exp1★ · 2022-05-29
- Xd-tl/CVE-2022-22947-Rce_POC7★ · 2022-03-04
- Zh0um1/CVE-2022-2294728★ · 2023-06-21
- aesm1p/CVE-2022-22947-POC-Reproduce0★ · 2022-04-05
- anansec/CVE-2022-22947_EXP7★ · 2022-05-19
- aodsec/CVE-2022-2294735★ · 2022-03-08
- bigbigban1/CVE-2022-22947-exp1★ · 2022-05-29
- bysinks/CVE-2022-229471★ · 2022-03-15
- carlosevieira/CVE-2022-2294737★ · 2022-03-04
- cc3305/CVE-2022-229470★ · 2024-07-27
- chaosec2021/EXP-POC26★ · 2023-01-11
- crowsec-edtech/CVE-2022-2294737★ · 2022-03-04
- d0ctorsec/LearnJavaMemshellFromZero-Recurrence95★ · 2026-06-15
- darkb1rd/cve-2022-229476★ · 2022-03-07
- dbgee/CVE-2022-229472★ · 2022-03-04
- debug4you/CVE-2022-229472★ · 2022-03-04
- dingxiao77/-cve-2022-22947-9★ · 2022-03-04
- fbion/CVE-2022-229470★ · 2022-03-04
- flying0er/CVE-2022-22947-goby0★ · 2022-03-04
- godzeo/SecGPT-distill-boundless9★ · 2025-05-03
- hh-hunter/cve-2022-22947-docker0★ · 2022-03-11
- hunzi0/CVE-2022-22947-Rce_POC7★ · 2022-03-04
- j-jasson/CVE-2022-22947-Spring-Cloud-Gateway-SpelRCE14★ · 2022-03-09
- kmahyyg/CVE-2022-229471★ · 2022-07-12
- lucksec/Spring-Cloud-Gateway-CVE-2022-22947223★ · 2022-03-03
- mamba-2021/EXP-POC26★ · 2023-01-11
- mostwantedduck/cve-poc1★ · 2022-03-11
- mrknow001/CVE-2022-229477★ · 2022-03-08
- nanaao/CVE-2022-22947-POC0★ · 2022-03-04
- nu0l/cve-2022-229473★ · 2022-03-04
- qq87234770/CVE-2022-229471★ · 2022-11-15
- runt0/woodpecker-box0★ · 2025-03-26
- safest-place/ExploitPcapCollection96★ · 2026-06-24
- savior-only/CVE-2022-22947680★ · 2026-06-26
- scopion/CVE-2022-22947-exp0★ · 2022-03-30
- scopion/cve-2022-229470★ · 2022-03-03
- shoucheng3/spring-cloud__spring-cloud-gateway_CVE-2022-22947_3-0-60★ · 2025-08-20
- skysliently/CVE-2022-22947-pb-ai0★ · 2025-08-08
- stayfoolish777/CVE-2022-22947-POC3★ · 2022-06-09
- talentsec/Spring-Cloud-Gateway-CVE-2022-229471★ · 2022-04-01
- tangxiaofeng7/CVE-2022-22947-Spring-Cloud-Gateway71★ · 2022-03-04
- twseptian/cve-2022-2294711★ · 2022-04-15
- viemsr/spring_cloud_gateway_memshell18★ · 2022-03-18
- whwlsfb/cve-2022-22947-godzilla-memshell210★ · 2022-04-26
- wjl110/Spring_CVE_2022_2294710★ · 2022-03-04
- MoCh3n/CVE-2022-22947-Spring-Cloud-Gateway-SpelRCE
- entr0pie/demo-cve-2022-22947
- 24-2021/fscan-POC
- onewinner/VulToolsKit
- reph0r/poc-exp
- shengshengli/fscan-POC
Nuclei templates (1)
Metasploit modules (1)
ExploitDB entries (1)
Vulhub environments (1)
Exploit collections (2)
- helloexp/0day/tree/master/00-CVE_EXP/CVE-2022-22947
- zan8in/afrog/blob/main/pocs/afrog-pocs/CVE/2022/CVE-2022-22947.yaml