In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2022-22963
This issue has been addressed in the following products: Openshift Serverless 1 on RHEL 8 Via RHSA-2022:1291 https://access.redhat.com/errata/RHSA-2022:1291
This issue has been addressed in the following products: Openshift Serveless 1.21 Via RHSA-2022:1292 https://access.redhat.com/errata/RHSA-2022:1292