In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote execution on the remote host.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.springframework.cloud:spring-cloud-gateway(Maven) | 0 | 3.0.7 | N/A |
| org.springframework.cloud:spring-cloud-gateway(Maven) | 3.1.0 | 3.1.1 | N/A |
CVSS Metrics