Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
spring-RCE-CVE-2022-22965 — CVE-2022-22965에 대한 교육용 분석 및 개념 증명 익스플로잇, JDK 9+ 및 Tomcat WAR 배포 환경에서 데이터 바인딩을 통한 Spring MVC/WebFlux 원격 코드 실행 취약점. | Kitploit
도구/GitHubGitHub/enokiy/spring-rce-cve-2022-22965
Vulnerability AnalysisCode AnalysisExploitationWeb Application ExploitationLearning & Education
GitHubenokiy/spring-rce-cve-2022-22965

spring-RCE-CVE-2022-22965

CVE-2022-22965에 대한 교육용 분석 및 개념 증명 익스플로잇, JDK 9+ 및 Tomcat WAR 배포 환경에서 데이터 바인딩을 통한 Spring MVC/WebFlux 원격 코드 실행 취약점.

저장소 보기
114년 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

취약점 개요

최근 Spring에서 대규모 CVE 취약점이 발견되었습니다. CVE 정보에 따르면 "A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.(JDK 9+에서 실행되는 Spring MVC 또는 Spring WebFlux 애플리케이션은 데이터 바인딩을 통한 원격 코드 실행(RCE)에 취약할 수 있습니다. 구체적인 악용을 위해서는 애플리케이션이 WAR 배포로 Tomcat에서 실행되어야 합니다. 애플리케이션이 Spring Boot 실행 가능 jar(기본값)로 배포된 경우 악용에 취약하지 않습니다. 그러나 취약점의 성격은 더 일반적이며 이를 악용할 수 있는 다른 방법이 있을 수 있습니다.)" 본 분석은 해당 CVE를 재현하여 취약점 원리를 학습합니다.

Java Bean API

Spring MVC의 매개변수 바인딩 원리를 살펴보기 전에 Java Bean 관련 API를 먼저 살펴보겠습니다.

  • Java Bean: 실제로는 일종의 규칙입니다. 클래스가 이 규칙을 만족하면 다른 특정 클래스에서 호출할 수 있습니다. 클래스가 Java Bean으로 사용될 때, 해당 클래스는 비공개 속성 집합을 포함하며, public get/is() 또는 set() 메서드를 통해 속성에 대한 읽기/쓰기 작업을 수행합니다.
  • Introspector: The Introspector class provides a standard way for tools to learn about the properties, events, and methods supported by a target Java Bean. For each of those three kinds of information, the Introspector will separately analyze the bean's class and superclasses looking for either explicit or implicit information and use that information to build a BeanInfo object that comprehensively describes the target bean.(Java는 Java Bean 클래스의 속성, 이벤트 및 메소드에 대한 기본 처리 방식을 제공합니다. 예를 들어, 특정 Bean 클래스의 속성/메소드를 찾을 때 현재 Bean 클래스에서 해당 속성을 찾지 못하면 Bean 클래스의 부모 클래스에서 찾는 규칙 등입니다.)
  • BeanInfo: Introspect on a Java Bean and learn about all its properties, exposed methods, and events. If the BeanInfo class for a Java Bean has been previously Introspected then the BeanInfo class is retrieved from the BeanInfo cache.(Java Bean을 내부 조사하여 모든 속성, 노출된 메소드 및 이벤트를 알아냅니다. Java Bean의 BeanInfo 클래스가 이전에 내부 조사된 경우 BeanInfo 클래스는 BeanInfo 캐시에서 검색됩니다.)
  • PropertyDescriptor: Java Bean이 accessor 메서드 집합을 통해 노출하는 속성을 설명합니다.

다음과 같은 Java Bean 클래스를 선언합니다:```java public class User { private String name;

public User() {
}
public void setName(String name) {
    this.name = name;
}
public String getName() {
    return this.name;
}
public int getAge() {
    return 18;
}

}

다음 테스트 코드를 통해 Introspector.getBeanInfo가 가져오는 정보를 확인해보겠습니다.```java
@Test
    public  void testIntrospector() throws IntrospectionException {
        BeanInfo beanInfo = Introspector.getBeanInfo(User.class);
        for (PropertyDescriptor pdesc:beanInfo.getPropertyDescriptors()){
            System.out.println("Property: " + pdesc.getName() + ",Class:" + pdesc.getPropertyType());
        }
//        for (MethodDescriptor md:beanInfo.getMethodDescriptors()) {
//            System.out.println("Method: " + md.getName());
//        }
    }

(no content provided)```text Property: age,Class:int Property: class,Class:class java.lang.Class Property: name,Class:class java.lang.String

예상한 age와 그 외에도 class 속성이 하나 더 있습니다. 클래스 이름은 Class입니다. 만약 계속해서 Introspector.getBeanInfo(Class.class)를 호출하면 classLoader 등 더 많은 정보를 얻을 수 있습니다:```text jdk11:
Property: annotatedInterfaces
Property: annotatedSuperclass
Property: annotation
Property: annotations
Property: anonymousClass
Property: array
Property: canonicalName
Property: class
Property: classLoader
Property: classes
Property: componentType
Property: constructors
Property: declaredAnnotations
Property: declaredClasses
Property: declaredConstructors
Property: declaredFields
Property: declaredMethods
Property: declaringClass
Property: enclosingClass
Property: enclosingConstructor
Property: enclosingMethod
Property: enum
Property: enumConstants
Property: fields
Property: genericInterfaces
Property: genericSuperclass
Property: interface
Property: interfaces
Property: localClass
Property: memberClass
Property: methods
Property: modifiers
Property: module
Property: name
Property: nestHost
Property: nestMembers
Property: package
Property: packageName
Property: primitive
Property: protectionDomain
Property: signers
Property: simpleName
Property: superclass
Property: synthetic
Property: typeName
Property: typeParameters

또한 다른 JDK 버전에서 Introspector.getBeanInfo(Class.class)로 얻은 정보의 차이를 비교해 보면, 위쪽은 jdk-11에서의 출력이고, 아래쪽은 JDK8에서의 출력입니다:```text jdk8: Property: annotatedInterfaces Property: annotatedSuperclass Property: annotation Property: annotations Property: anonymousClass Property: array Property: canonicalName Property: class Property: classLoader Property: classes Property: componentType Property: constructors Property: declaredAnnotations Property: declaredClasses Property: declaredConstructors Property: declaredFields Property: declaredMethods Property: declaringClass Property: enclosingClass Property: enclosingConstructor Property: enclosingMethod Property: enum Property: enumConstants Property: fields Property: genericInterfaces Property: genericSuperclass Property: interface Property: interfaces Property: localClass Property: memberClass Property: methods Property: modifiers Property: name Property: package Property: primitive Property: protectionDomain Property: signers Property: simpleName Property: superclass Property: synthetic Property: typeName Property: typeParameters

````text
Property: annotatedInterfaces
Property: annotatedSuperclass
Property: annotation
Property: annotations
Property: anonymousClass
Property: array
Property: canonicalName
Property: class
Property: classLoader
Property: classes
Property: componentType
Property: constructors
Property: declaredAnnotations
Property: declaredClasses
Property: declaredConstructors
Property: declaredFields
Property: declaredMethods
Property: declaringClass
Property: enclosingClass
Property: enclosingConstructor
Property: enclosingMethod
Property: enum
Property: enumConstants
Property: fields
Property: genericInterfaces
Property: genericSuperclass
Property: interface
Property: interfaces
Property: localClass
Property: memberClass
Property: methods
Property: modifiers
Property: module
Property: name
Property: package
Property: packageName
Property: primitive
Property: protectionDomain
Property: signers
Property: simpleName
Property: superclass
Property: synthetic
Property: typeName
Property: typeParameters

jdk9는 JDK8에 비해 module과 packageName 두 가지 속성이 더 있으며, JDK11에서는 module과 packageName 속성 외에도 nestHost와 nestMembers라는 두 가지 속성이 더 있습니다.

도구 다운로드