Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. com.nepxion/discovery
  4. ›
  5. CVE-2022-23463

CVE-2022-23463: Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')

September 24, 2022 (updated September 28, 2022)

Nepxion Discovery is a solution for Spring Cloud. Discover is vulnerable to SpEL Injection in discovery-commons. DiscoveryExpressionResolver’s eval method is evaluating expression with a StandardEvaluationContext, allowing the expression to reach and interact with Java classes such as java.lang.Runtime, leading to Remote Code Execution. There is no patch available for this issue at time of publication. There are no known workarounds.

References

  • nvd.nist.gov/vuln/detail/CVE-2022-23463
  • securitylab.github.com/advisories/GHSL-2022-033_GHSL-2022-034_Discovery/

Code Behaviors & Features

Detect and mitigate CVE-2022-23463 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions up to 6.16.2

Solution

Unfortunately, there is no solution available yet.

Impact 9.8 CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-917: Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')

Source file

maven/com.nepxion/discovery/CVE-2022-23463.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:19 +0000.