CVE-2022-46166 HIGH

CVE-2022-46166: Spring Boot Admins integrated notifier support allows arbitrary code execution

Vendor Codecentric
Product spring-boot-admin
Weakness CWE-94 · Code injection
Published December 9, 2022
Last update April 23, 2025

CVSS base score

8.1/10
Attack vector Network
Attack complexity High
Privileges required Low
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

Spring boot admins is an open source administrative user interface for management of spring boot applications. All users who run Spring Boot Admin Server, having enabled Notifiers (e.g. Teams-Notifier) and write access to environment variables via UI are affected. Users are advised to upgrade to the most recent releases of Spring Boot Admin 2.6.10 and 2.7.8 to resolve this issue. Users unable to upgrade may disable any notifier or disable write access (POST request) on `/env` actuator endpoint.

Key dates

02Disclosure timeline

December 9, 2022 CVE published
April 23, 2025 Record updated