This Metasploit module exploits an unauthenticated remote code execution vulnerability in Spring Cloud Gateway versions 3.0.0 through 3.0.6 and 3.1.0. The vulnerability can be exploited when the Gateway Actuator endpoint is enabled, exposed and unsecured. An unauthenticated attacker can use SpEL expressions to execute code and take control of the victim machine.
21645b3916729fad4fc93eb22039c634ac8ba5e477c97ca0844e7968d2668c3d
Spring Cloud Gateway version 3.1.0 suffers from a remote code execution vulnerability.
f9d18c9ee39c9cd35731f202ab51b6291925e1c7ed9abc366f47ad1b7b4f8e6a