Ripple Treasury was informed of a vulnerability (CVE-2010-1622963) Spring Cloud Function – Remote Code Execution.
Please note, we do not use Java programming language in our development, and at this time, we have no reason to believe that there is any associated risk to our customers or services.
However, we take all security related issues extremely seriously, we continue to exercise caution; we have taken the following steps:
We have scanned our systems and code, library specifically for the Spring vulnerability
We have verified with our intrusion detection partner (Alert Logic) to ensure they have added CVE-2010-1622963 to their library for continual scanning and alerting
If, through our investigation, we learn of any customer impact, we will promptly notify any affected customers and provide them with information necessary to remedy related risks in a timely and effective manner.
You can find out more information regarding CVE-2010-1622963, here:
CVE-2022-22963: Remote code execution in Spring Cloud Function by malicious Spring ExpressionYou can find out more information regarding Alert Logic’s Emerging Threat process here: https://support.alertlogic.com/hc/en-us/articles/5070669818523-03-31-2022-Spring4Shell-Java-Spring-Zero-Day-Vulnerability
Copyright 2025 Ripple Labs Inc.
