CVE-2022-22947: VMware Spring Cloud Gateway Code Injection Vulnerability
Spring Cloud Gateway applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. Required action: Apply updates per vendor instructions.
CISA KEV ↗ · unattributed attribution