Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
spring-RCE-CVE-2022-22965 — Educational analysis and proof-of-concept exploit for CVE-2022-22965, a Spring MVC/WebFlux remote code execution vulnerability via data binding on JDK 9+ with Tomcat WAR deployment. | Kitploit
Tools/GitHubGitHub/enokiy/spring-rce-cve-2022-22965
Vulnerability AnalysisCode AnalysisExploitationWeb Application ExploitationLearning & Education
GitHubenokiy/spring-rce-cve-2022-22965

spring-RCE-CVE-2022-22965

Educational analysis and proof-of-concept exploit for CVE-2022-22965, a Spring MVC/WebFlux remote code execution vulnerability via data binding on JDK 9+ with Tomcat WAR deployment.

View Repository
124 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Vulnerability Overview

Recently, Spring released a major CVE vulnerability. The CVE information states: "A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it (Spring MVC or Spring WebFlux applications running on JDK 9+ may be vulnerable to remote code execution via data binding. The specific exploit requires the application to be deployed as a war package on Tomcat. If the application is deployed as a Spring Boot executable jar, i.e., the default, it is not vulnerable. However, the nature of the vulnerability is more general, and there may be other ways to exploit it)." This analysis learns the vulnerability principle through reproduction of this CVE.

Java Bean API

Before looking at the principle of Spring MVC parameter binding, let's first take a look at some APIs related to Java Beans.

  • Java Bean: Actually a specification, when a class meets this specification, it can be called by other specific classes. When a class is used as a Java Bean, it contains a set of private properties, and reads and writes properties through public get/is() or set() methods.
  • Introspector (introspection): The Introspector class provides a standard way for tools to learn about the properties, events, and methods supported by a target Java Bean. For each of those three kinds of information, the Introspector will separately analyze the bean's class and superclasses looking for either explicit or implicit information and use that information to build a BeanInfo object that comprehensively describes the target bean. (The default processing method provided by Java for the properties, events, and methods of Java Bean classes. For example, when looking for a property/method of a bean class, if the property is not found in the current bean class, it searches in the parent class of the bean class, etc.)
  • BeanInfo: Introspect on a Java Bean and learn about all its properties, exposed methods, and events. If the BeanInfo class for a Java Bean has been previously Introspected then the BeanInfo class is retrieved from the BeanInfo cache. (Introspect a Java Bean and understand all its properties, exposed methods, and events. If the BeanInfo class for a Java Bean has been previously introspected, then the BeanInfo class is retrieved from the BeanInfo cache.)
  • PropertyDescriptor: Used to describe the properties exposed by a Java Bean through a set of accessor methods.

Declare the following Java bean class:```java public class User { private String name;

public User() {
}
public void setName(String name) {
    this.name = name;
}
public String getName() {
    return this.name;
}
public int getAge() {
    return 18;
}

}

Use the following test code to see the information obtained by Introspector.getBeanInfo:```java
@Test
    public  void testIntrospector() throws IntrospectionException {
        BeanInfo beanInfo = Introspector.getBeanInfo(User.class);
        for (PropertyDescriptor pdesc:beanInfo.getPropertyDescriptors()){
            System.out.println("Property: " + pdesc.getName() + ",Class:" + pdesc.getPropertyType());
        }
//        for (MethodDescriptor md:beanInfo.getMethodDescriptors()) {
//            System.out.println("Method: " + md.getName());
//        }
    }

(empty)```text Property: age,Class:int Property: class,Class:class java.lang.Class Property: name,Class:class java.lang.String

Apart from the expected `age` and `that`, there is also a `class` attribute with the class name `Class`. If you continue to call `Introspector.getBeanInfo(Class.class)`, you can obtain more information such as `classLoader`:```text jdk11:
Property: annotatedInterfaces
Property: annotatedSuperclass
Property: annotation
Property: annotations
Property: anonymousClass
Property: array
Property: canonicalName
Property: class
Property: classLoader
Property: classes
Property: componentType
Property: constructors
Property: declaredAnnotations
Property: declaredClasses
Property: declaredConstructors
Property: declaredFields
Property: declaredMethods
Property: declaringClass
Property: enclosingClass
Property: enclosingConstructor
Property: enclosingMethod
Property: enum
Property: enumConstants
Property: fields
Property: genericInterfaces
Property: genericSuperclass
Property: interface
Property: interfaces
Property: localClass
Property: memberClass
Property: methods
Property: modifiers
Property: module
Property: name
Property: nestHost
Property: nestMembers
Property: package
Property: packageName
Property: primitive
Property: protectionDomain
Property: signers
Property: simpleName
Property: superclass
Property: synthetic
Property: typeName
Property: typeParameters

Also, compare the differences in the information obtained by Introspector.getBeanInfo(Class.class) under different JDK versions. The above is the output under jdk-11, and the below is the output under JDK8:```text jdk8: Property: annotatedInterfaces Property: annotatedSuperclass Property: annotation Property: annotations Property: anonymousClass Property: array Property: canonicalName Property: class Property: classLoader Property: classes Property: componentType Property: constructors Property: declaredAnnotations Property: declaredClasses Property: declaredConstructors Property: declaredFields Property: declaredMethods Property: declaringClass Property: enclosingClass Property: enclosingConstructor Property: enclosingMethod Property: enum Property: enumConstants Property: fields Property: genericInterfaces Property: genericSuperclass Property: interface Property: interfaces Property: localClass Property: memberClass Property: methods Property: modifiers Property: name Property: package Property: primitive Property: protectionDomain Property: signers Property: simpleName Property: superclass Property: synthetic Property: typeName Property: typeParameters

这是 README 的第十一部分翻译。```text
Property: annotatedInterfaces
Property: annotatedSuperclass
Property: annotation
Property: annotations
Property: anonymousClass
Property: array
Property: canonicalName
Property: class
Property: classLoader
Property: classes
Property: componentType
Property: constructors
Property: declaredAnnotations
Property: declaredClasses
Property: declaredConstructors
Property: declaredFields
Property: declaredMethods
Property: declaringClass
Property: enclosingClass
Property: enclosingConstructor
Property: enclosingMethod
Property: enum
Property: enumConstants
Property: fields
Property: genericInterfaces
Property: genericSuperclass
Property: interface
Property: interfaces
Property: localClass
Property: memberClass
Property: methods
Property: modifiers
Property: module
Property: name
Property: package
Property: packageName
Property: primitive
Property: protectionDomain
Property: signers
Property: simpleName
Property: superclass
Property: synthetic
Property: typeName
Property: typeParameters

JDK9 adds two attributes, module and packageName, compared to JDK8. In JDK11, besides module and packageName, there are two additional attributes: nestHost and nestMembers.

Download Tool