spring-cloud-gateway-server is vulnerable to Expression Language Injection
95
Critical Risk
Affected versions of this package are vulnerable to Expression Language (EL) injection in the GatewayEvaluationContext method, which allows attackers to modify properties and ultimately achieve remote code execution. This issue only affects WebFlux applications; WebMVC applications are not impacted.
You are affected if you are using a version that falls within the vulnerable range, and you expose the /actuator/gateway actuator endpoint via e.g. the Spring configuration setting management.endpoints.web.exposure.include=gateway (typically set via application.properties) in your Spring deployment/application.
spring-cloud-gateway-server is vulnerable to Expression Language Injection in versions 3.0.0 - 3.1.10, 4.0.0 - 4.1.10, 4.2.0 - 4.2.4 and 4.3.0 - 4.3.0.
Upgrade the org.springframework.cloud:spring-cloud-gateway-server library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant