
Spring Framework CVE-2022-22965 本地影响条件验证、版本升级修复与复测项目
This project is used for learning and verifying the impact conditions, risk manifestations, remediation methods, and post-remediation re-testing procedures for Spring Framework CVE-2022-22965, also known as the Spring4Shell vulnerability.
The project was completed in a locally built authorized environment. The focus of the project is not on attacking real targets, but on building pre- and post-remediation Spring MVC test environments, verifying the vulnerability-related impact conditions item by item, and observing the differences in internal property path access in the Spring data binding before and after version upgrades in a safe, controlled read-only manner.
This project completed the following process:
This project is only intended for personal local self-built environments or explicitly authorized security testing environments.
The project does not scan, probe, or exploit any public websites, servers, or third-party business systems, and does not contain real user data or real business data.
The following operations were NOT performed during testing:
It is prohibited to use the test methods in this project on any unauthorized targets.
CVE-2022-22965, commonly known as Spring4Shell, is a remote code execution vulnerability related to the request parameter data binding mechanism in Spring Framework.
Spring MVC supports automatically binding HTTP request parameters to Java object properties. For example, this project receives name and email parameters through the following method:
@ModelAttribute("profile") UserProfile profile
Under normal circumstances, the request parameters name and email are bound to the UserProfile object according to property names.
In the affected versions, access restrictions on some internal property paths are not strict enough. When using JDK 9 or higher, and when specific Servlet container, deployment method, and data binding conditions are met, external request parameters may access internal objects related to Java Class, modules, class loaders, or the container along the ordinary business object.
In a specific exploitable environment, an attacker may further modify server configurations or write server files, thereby creating a remote code execution risk.
This project does not perform full remote code exploitation; instead, it uses the following property path for safe, read-only differential diagnosis:
class.module.name
This project was completed in a personal local VMware isolated experimental environment.
127.0.0.1Normal functionality test data:
Alice[email protected]Security diagnostic property path:
class.module.name
spring4shell-local-verification-lab/
README.md: Project introduction, test methodology, verification results, and remediation explanationdocs/: Spring4Shell local impact condition verification, remediation, and re-testing reportimages/: Screenshots of the project environment, testing process, and re-testingvulnerable-demo/: Pre-remediation project using Spring Framework 5.3.17fixed-demo/: Post-remediation project using Spring Framework 5.3.18notes/: Study notes and process recordsMain source code structure:
config/: Spring MVC configuration classes and application initializer classescontroller/: Form processing and property path diagnostic controllermodel/: UserProfile class for receiving name and email parametersWEB-INF/views/: JSP pages for homepage, submission result, and diagnostic resultThis project sets up two Spring MVC applications: one pre-remediation and one post-remediation.
Project directory:
vulnerable-demo
Version used:
Spring Framework 5.3.17
Generated WAR file:
spring4shell-vulnerable-demo.war
Access address:
http://127.0.0.1:8080/spring4shell-vulnerable-demo/
Diagnostic page:
http://127.0.0.1:8080/spring4shell-vulnerable-demo/binding-probe
Project directory:
fixed-demo
Version used:
Spring Framework 5.3.18
Generated WAR file:
spring4shell-fixed-demo.war
Access address:
http://127.0.0.1:8080/spring4shell-fixed-demo/
Diagnostic page:
http://127.0.0.1:8080/spring4shell-fixed-demo/binding-probe
The test project provides a simple user profile form, including:
The controller receives request parameters through the following method:
@ModelAttribute("profile") UserProfile profile
After the user submits the name and email, Spring MVC automatically binds the name and email parameters to the UserProfile object.
The result page reads the bound object and displays the user's submitted name and email.
This functionality is used to confirm that the project runs normally, and to prove that a valid Spring MVC request parameter data binding entry exists in the application.
This project follows the approach: "first confirm normal functionality, then confirm impact conditions, then perform read-only risk diagnosis, and finally fix and re-test."