Spring Cloud Gateway 3.1.0 with the gateway actuator exposed without authentication, vulnerable to CVE-2022-22947: a route added through /actuator/gateway/routes carries a filter argument evaluated as a SpEL expression on refresh, which runs commands.
Pas commencéDockercommit 678badcx86_64 · aarch64Secret
Exploit CVE-2022-22947 through the gateway actuator to run commands and get a shell.
Le brief de ce lab se trouve dans son dépôt.