In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
Under investigation. Affected products will be promptly added as each investigation is completed.
Product Family | Products |
ACI-E | All products |
ADTRAN OS IP Business Gateways, Routers, & Switches |
|
Carrier Ethernet NIDs |
|
EPON OLTs |
|
EPON ONUs |
|
Ethernet Service Delivery Gateways & Mesh APs (PlumeOS) | All products |
Ethernet Service Delivery Gateways & Mesh APs (SmartOS) | All products |
GPON, XGS-PON, & Active Ethernet ONUs |
|
GPON & XGS-PON Service Delivery Gateways |
|
hiX | All products |
Mosaic Cloud Platform | All products |
Mosaic Cloud Platform Plugins | All products |
n-Command MSP | All products |
OPTI Series | All products |
SDX 6000 Series OLTs |
|
SDX 8000 Series Aggregation Switches | All products |
SmartRG Ethernet Residential Gateways & Mesh APs |
|
SmartRG VDSL2 Residential Gateways |
|
Total Access 1100 & 1200 Series | All products |
Total Access 5000 | All products |
Revision | Date | Changes |
B | 2022-04-06 | Added ACI-E, Ethernet Service Delivery Gateways & Mesh APs (PlumeOS), hiX, Mosaic Cloud Platform, and n-Command MSP as unaffected products. Updated EPON OLTs, Ethernet Service Delivery Gateways & Mesh APs (SmartOS), and Mosaic Cloud Platform Plugins. |
A | 2022-04-01 | Initial release. |