// For flags

CVE-2022-23463

SpEL Injection in Nepxion Discovery

Severity Score

9.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Nepxion Discovery is a solution for Spring Cloud. Discover is vulnerable to SpEL Injection in discovery-commons. DiscoveryExpressionResolver’s eval method is evaluating expression with a StandardEvaluationContext, allowing the expression to reach and interact with Java classes such as java.lang.Runtime, leading to Remote Code Execution. There is no patch available for this issue at time of publication. There are no known workarounds.

Nepxion Discovery es una solución para Spring Cloud. Discover es vulnerable a una inyección de SpEL en discovery-commons. El método eval de DiscoveryExpressionResolver evalúa la expresión con un StandardEvaluationContext, permitiendo a la expresión alcanzar e interactuar con clases Java como java.lang.Runtime, conllevando a una ejecución de código remota. No se presenta ningún parche disponible para este problema en el momento de la publicación. No se presentan mitigaciones conocidas.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
Low
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-01-19 CVE Reserved
  • 2022-09-24 CVE Published
  • 2024-04-16 EPSS Updated
  • 2024-08-03 CVE Updated
  • 2024-08-03 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-917: Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Nepxion
Search vendor "Nepxion"
Discovery
Search vendor "Nepxion" for product "Discovery"
<= 6.16.2
Search vendor "Nepxion" for product "Discovery" and version " <= 6.16.2"
spring_cloud
Affected