Skip to content
KitploitKITPLOIT
उपकरणएक्सप्लॉइटब्लॉग
Log in
जमा करें
उपकरणएक्सप्लॉइटब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

फ़ीडसंपर्कगोपनीयता© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
spring-RCE-CVE-2022-22965 — Educational analysis and proof-of-concept exploit for CVE-2022-22965, a Spring MVC/WebFlux remote code execution vulnerability via data binding on JDK 9+ with Tomcat WAR deployment. | Kitploit
उपकरण/GitHubGitHub/enokiy/spring-rce-cve-2022-22965
भेद्यता विश्लेषणकोड विश्लेषणशोषणवेब एप्लिकेशन शोषणलर्निंग और शिक्षा
GitHubenokiy/spring-rce-cve-2022-22965

spring-RCE-CVE-2022-22965

Educational analysis and proof-of-concept exploit for CVE-2022-22965, a Spring MVC/WebFlux remote code execution vulnerability via data binding on JDK 9+ with Tomcat WAR deployment.

रिपॉजिटरी देखें
124 साल पहलेअभी तक समीक्षित नहीं

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें

भेद्यता परिचय

हाल ही में Spring में एक बड़ा CVE भेद्यता सामने आया है। CVE जानकारी के अनुसार, "JDK 9+ पर चलने वाला Spring MVC या Spring WebFlux एप्लिकेशन डेटा बाइंडिंग के माध्यम से रिमोट कोड एक्ज़ीक्यूशन (RCE) के लिए संवेदनशील हो सकता है। विशिष्ट एक्सप्लॉइट के लिए एप्लिकेशन को Tomcat पर WAR डिप्लॉयमेंट के रूप में चलाना आवश्यक है। यदि एप्लिकेशन Spring Boot एक्ज़ीक्यूटेबल जार के रूप में डिप्लॉय किया गया है, अर्थात डिफ़ॉल्ट, तो यह एक्सप्लॉइट के लिए संवेदनशील नहीं है। हालांकि, भेद्यता की प्रकृति अधिक सामान्य है, और इसका शोषण करने के अन्य तरीके भी हो सकते हैं।" इस विश्लेषण का उद्देश्य इस CVE को पुन: प्रस्तुत करके भेद्यता के सिद्धांत को सीखना है।

जावा बीन API

स्प्रिंगएमवीसी के पैरामीटर बाइंडिंग सिद्धांत को देखने से पहले, आइए पहले जावा बीन से संबंधित कुछ API को देखें।

  • java Bean: वास्तव में यह एक विनिर्देश है। जब कोई क्लास इस विनिर्देश को पूरा करता है, तो इस क्लास को अन्य विशिष्ट क्लास द्वारा कॉल किया जा सकता है। जब किसी क्लास को java Bean के रूप में उपयोग किया जाता है, तो उसमें निजी गुणों का एक सेट होता है, और public get/is() या set() विधियों के माध्यम से गुणों को पढ़ा और लिखा जाता है।
  • Introspector: The Introspector class provides a standard way for tools to learn about the properties, events, and methods supported by a target Java Bean. For each of those three kinds of information, the Introspector will separately analyze the bean's class and superclasses looking for either explicit or implicit information and use that information to build a BeanInfo object that comprehensively describes the target bean.(जावा बीन क्लास के गुणों, घटनाओं और विधियों के लिए जावा द्वारा प्रदान की गई डिफ़ॉल्ट हैंडलिंग विधि। उदाहरण के लिए, किसी बीन क्लास के गुण/विधि की खोज करते समय, यदि वर्तमान बीन क्लास में यह गुण नहीं मिलता है, तो बीन क्लास के पैरेंट क्लास में खोज की जाती है, आदि।)
  • BeanInfo: Introspect on a Java Bean and learn about all its properties, exposed methods, and events. If the BeanInfo class for a Java Bean has been previously Introspected then the BeanInfo class is retrieved from the BeanInfo cache.(जावा बीन का इंट्रोस्पेक्ट करें और इसके सभी गुणों, उजागर विधियों और घटनाओं को जानें। यदि किसी जावा बीन के लिए BeanInfo क्लास पहले इंट्रोस्पेक्ट किया गया है, तो BeanInfo क्लास को BeanInfo कैश से प्राप्त किया जाता है।)
  • PropertyDescriptor: इसका उपयोग जावा बीन द्वारा एक्सेसर विधियों के सेट के माध्यम से उजागर किए गए गुणों का वर्णन करने के लिए किया जाता है।

निम्नलिखित java bean क्लास घोषित करें:```java public class User { private String name;

public User() {
}
public void setName(String name) {
    this.name = name;
}
public String getName() {
    return this.name;
}
public int getAge() {
    return 18;
}

}

निम्नलिखित परीक्षण कोड के साथ देखें कि Introspector.getBeanInfo द्वारा प्राप्त जानकारी क्या है:```java
@Test
    public  void testIntrospector() throws IntrospectionException {
        BeanInfo beanInfo = Introspector.getBeanInfo(User.class);
        for (PropertyDescriptor pdesc:beanInfo.getPropertyDescriptors()){
            System.out.println("Property: " + pdesc.getName() + ",Class:" + pdesc.getPropertyType());
        }
//        for (MethodDescriptor md:beanInfo.getMethodDescriptors()) {
//            System.out.println("Method: " + md.getName());
//        }
    }

आउटपुट:```text Property: age,Class:int Property: class,Class:class java.lang.Class Property: name,Class:class java.lang.String

पूर्वानुमानित age और उसके अलावा, एक class गुण भी है, जिसका नाम Class है। यदि आगे Introspector.getBeanInfo(Class.class) को कॉल किया जाए तो classLoader जैसी अधिक जानकारी प्राप्त की जा सकती है:```text jdk11:
Property: annotatedInterfaces
Property: annotatedSuperclass
Property: annotation
Property: annotations
Property: anonymousClass
Property: array
Property: canonicalName
Property: class
Property: classLoader
Property: classes
Property: componentType
Property: constructors
Property: declaredAnnotations
Property: declaredClasses
Property: declaredConstructors
Property: declaredFields
Property: declaredMethods
Property: declaringClass
Property: enclosingClass
Property: enclosingConstructor
Property: enclosingMethod
Property: enum
Property: enumConstants
Property: fields
Property: genericInterfaces
Property: genericSuperclass
Property: interface
Property: interfaces
Property: localClass
Property: memberClass
Property: methods
Property: modifiers
Property: module
Property: name
Property: nestHost
Property: nestMembers
Property: package
Property: packageName
Property: primitive
Property: protectionDomain
Property: signers
Property: simpleName
Property: superclass
Property: synthetic
Property: typeName
Property: typeParameters

इसके अलावा, विभिन्न JDK संस्करणों के अंतर्गत Introspector.getBeanInfo(Class.class) द्वारा प्राप्त जानकारी के अंतर की तुलना करें, ऊपर वाला jdk-11 का आउटपुट है, नीचे वाला JDK8 का आउटपुट है:```text jdk8: Property: annotatedInterfaces Property: annotatedSuperclass Property: annotation Property: annotations Property: anonymousClass Property: array Property: canonicalName Property: class Property: classLoader Property: classes Property: componentType Property: constructors Property: declaredAnnotations Property: declaredClasses Property: declaredConstructors Property: declaredFields Property: declaredMethods Property: declaringClass Property: enclosingClass Property: enclosingConstructor Property: enclosingMethod Property: enum Property: enumConstants Property: fields Property: genericInterfaces Property: genericSuperclass Property: interface Property: interfaces Property: localClass Property: memberClass Property: methods Property: modifiers Property: name Property: package Property: primitive Property: protectionDomain Property: signers Property: simpleName Property: superclass Property: synthetic Property: typeName Property: typeParameters

[No input content provided to translate.]```text
Property: annotatedInterfaces
Property: annotatedSuperclass
Property: annotation
Property: annotations
Property: anonymousClass
Property: array
Property: canonicalName
Property: class
Property: classLoader
Property: classes
Property: componentType
Property: constructors
Property: declaredAnnotations
Property: declaredClasses
Property: declaredConstructors
Property: declaredFields
Property: declaredMethods
Property: declaringClass
Property: enclosingClass
Property: enclosingConstructor
Property: enclosingMethod
Property: enum
Property: enumConstants
Property: fields
Property: genericInterfaces
Property: genericSuperclass
Property: interface
Property: interfaces
Property: localClass
Property: memberClass
Property: methods
Property: modifiers
Property: module
Property: name
Property: package
Property: packageName
Property: primitive
Property: protectionDomain
Property: signers
Property: simpleName
Property: superclass
Property: synthetic
Property: typeName
Property: typeParameters

jdk9 में JDK8 की तुलना में दो अतिरिक्त विशेषताएँ हैं: module और packageName, जबकि JDK11 में module और packageName के अलावा दो और विशेषताएँ हैं: nestHost और nestMembers।

data binding डेटा बाइंडिंग

टूल डाउनलोड करें