CVE-2025-41243: Why "Property Modification" Undersells the Blast Radius
CVE-2025-41243 (CVSS 10.0) in Spring Cloud Gateway: with the actuator exposed, 'property modification' reaches arbitrary file read and SSRF to cloud metadata.
Feng Ning
7 min read min read