2022-04-02 14:23:09 +08:00

1.1 KiB

Spring Core Framework Remote Code Execution Vulnerability(CVE-2022-22965)

Spring core is a toolkit for discovering, creating and processing the relationship between beans in the Spring series.An unauthenticated attacker could use this vulnerability for remote arbitrary code execution. The vulnerability exists widely in the Spring framework and derived frameworks, and JDK 9.0 and above will be affected. Products using older JDK versions are not affected.

FOFA query rule: app="APACHE-Tomcat" || app="vmware-SpringBoot-framework" || app="vmware-SpringBoot-framework" || app="vmware-Spring-Batch" || app="vmware-Spring-framework" || app="vmware-Spring-Security"

Demo

Spring_Core_Framework_Remote_Code_Execution_Vulnerability