CVE-2021-22053 is a critical Remote Code Execution (RCE) vulnerability affecting applications that combine Spring Cloud Netflix Hystrix Dashboard with Spring Boot Starter Thymeleaf. Specifically, it allows attackers to execute arbitrary code by injecting SpringEL expressions into the request URI path when accessing the /hystrix/monitor endpoint. This vulnerability carries a high CVSS score of 8.8, indicating a network-exploitable flaw with low attack complexity and high impact on confidentiality, integrity, and availability. While not listed on CISA's KEV catalog, a Nuclei template for exploitation exists, and its EPSS score of 0.876 suggests a high likelihood of exploitation, despite limited public discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.2.0, < 2.2.10CPE matchmatch criteria | cpe:2.3:a:vmware:spring_cloud_netflix:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.