logo

Spring Cloud Framework Vulnerabilities

ID: ca5d0f27-c674-5930-b791-b6d852f33cf9

STIX ID: report--ca5d0f27-c674-5930-b791-b6d852f33cf9

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

**Zscaler ThreatLabz advisory:** Two vulnerabilities affecting Spring components are detailed: CVE-2022-22963 (medium severity SpEL expression/resource access issue in Spring Cloud Function that can be triggered via the spring.cloud.function.routing-expression HTTP header) and CVE-2022-22965 (Spring4Shell, a critical unauthenticated RCE in Spring Framework on JDK9+ under certain servlet/container configurations). The report lists impacted versions, patched releases (Spring Cloud Function 3.1.7/3.2.3; Spring Framework 5.3.18+/5.2.20+), mitigation guidance, recommended best practices, and Zscaler protections for known proofs-of-concept.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.