Two serious remote-code-execution vulnerabilities have been discovered in widely used Spring IO. At least one of the flaws is actively being exploited in the wild. Proof-of-concept exploits reportedly exist for both flaws. The Spring Cloud Function vulnerability tracked as CVE-2022-22963 is remotely exploitable under the default configuration of a Spring Boot application that depends on the Spring Cloud function. The vulnerability affects Spring MVC and Spring WebFlux applications running on JDK 9+.”]
Source: https://www.govinfosecurity.com/springshell-spring-cloud-function-bugs-need-urgent-patching-a-18822

