Skip to content
KitploitKITPLOIT
ИнструментыЭксплойтыБлог
Log in
Отправить
ИнструментыЭксплойтыБлог
Отправить

Инструменты для хакинга, пентеста и кибербезопасности — ваш арсенал защиты!

Kitploit — это каталог инструментов для хакинга, кибербезопасности и пентестинга. Находите последние обновления проектов для поиска уязвимостей, анализа систем, автоматизации тестирования и усиления вашей безопасности.

ЛентыКонтактыКонфиденциальность© 2026 Kitploit

Каталог инструментов

Категории

Все категории
Loading categories
spring-RCE-CVE-2022-22965 — Образовательный анализ и эксплойт для доказательства концепции для CVE-2022-22965, уязвимости удаленного выполнения кода в Spring MVC/WebFlux через связывание данных на JDK 9+ с развертыванием Tomcat WAR. | Kitploit
Инструменты/GitHubGitHub/enokiy/spring-rce-cve-2022-22965
Анализ уязвимостейАнализ КодаЭксплуатацияЭксплуатация веб-приложенийОбучение и Образование
GitHubenokiy/spring-rce-cve-2022-22965

spring-RCE-CVE-2022-22965

Образовательный анализ и эксплойт для доказательства концепции для CVE-2022-22965, уязвимости удаленного выполнения кода в Spring MVC/WebFlux через связывание данных на JDK 9+ с развертыванием Tomcat WAR.

Репозиторий
124 лет назадЕщё не проверено

Популярное

Смотреть все →

Откройте для себя самые используемые инструменты нашего сообщества.

Изучить все инструменты

Просмотрите нашу коллекцию инструментов

Смотреть все инструменты →
Поделиться

Описание уязвимости

Недавно в Spring была обнаружена серьезная уязвимость CVE. Согласно информации CVE, "A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it. (Приложения Spring MVC или Spring WebFlux, работающие на JDK 9+, могут быть уязвимы для удаленного выполнения кода (RCE) через привязку данных. Для конкретной эксплуатации требуется, чтобы приложение было развернуто как WAR на Tomcat. Если приложение развернуто как исполняемый jar Spring Boot (по умолчанию), оно не уязвимо для данной эксплуатации. Однако природа уязвимости более общая, и могут существовать другие способы ее эксплуатации.)". В данном анализе мы изучаем принцип уязвимости, воспроизводя этот CVE.

Java Bean API

Прежде чем рассматривать принцип привязки параметров Spring MVC, давайте посмотрим на некоторые API, связанные с Java Bean.

  • Java Bean: По сути, это спецификация. Когда класс соответствует этой спецификации, он может быть вызван другими определенными классами. При использовании класса в качестве Java Bean он содержит набор приватных свойств, которые читаются и записываются через публичные методы get/is() или set().
  • Introspector (Интроспекция): The Introspector class provides a standard way for tools to learn about the properties, events, and methods supported by a target Java Bean.
    For each of those three kinds of information, the Introspector will separately analyze the bean's class and superclasses looking for either explicit or implicit information and use that information to build a BeanInfo object that comprehensively describes the target bean. (Java предоставляет стандартный способ обработки свойств, событий и методов для классов Java Bean. Например, при поиске свойства/метода в классе bean, если оно не найдено в текущем классе, поиск продолжается в родительском классе и т.д.)
  • BeanInfo: Introspect on a Java Bean and learn about all its properties, exposed methods, and events.If the BeanInfo class for a Java Bean has been previously Introspected then the BeanInfo class is retrieved from the BeanInfo cache. (Выполняет интроспекцию Java Bean и предоставляет информацию обо всех его свойствах, открытых методах и событиях. Если класс BeanInfo для Java Bean уже был проинтроспектирован ранее, то он извлекается из кэша BeanInfo.)
  • PropertyDescriptor: Используется для описания свойств Java Bean, которые раскрываются через набор accessor methods (методов доступа).

Объявим следующий класс Java Bean:```java public class User { private String name;

public User() {
}
public void setName(String name) {
    this.name = name;
}
public String getName() {
    return this.name;
}
public int getAge() {
    return 18;
}

}

Используйте следующий тестовый код, чтобы увидеть информацию, полученную с помощью Introspector.getBeanInfo:```java
@Test
    public  void testIntrospector() throws IntrospectionException {
        BeanInfo beanInfo = Introspector.getBeanInfo(User.class);
        for (PropertyDescriptor pdesc:beanInfo.getPropertyDescriptors()){
            System.out.println("Property: " + pdesc.getName() + ",Class:" + pdesc.getPropertyType());
        }
//        for (MethodDescriptor md:beanInfo.getMethodDescriptors()) {
//            System.out.println("Method: " + md.getName());
//        }
    }

вывод:```text Property: age,Class:int Property: class,Class:class java.lang.Class Property: name,Class:class java.lang.String

Помимо ожидаемых `age` и `того`, также есть атрибут `class`, имя класса — `Class`. Если продолжить вызов `Introspector.getBeanInfo(Class.class)`, можно получить дополнительную информацию, такую как `classLoader`:```text jdk11:
Property: annotatedInterfaces
Property: annotatedSuperclass
Property: annotation
Property: annotations
Property: anonymousClass
Property: array
Property: canonicalName
Property: class
Property: classLoader
Property: classes
Property: componentType
Property: constructors
Property: declaredAnnotations
Property: declaredClasses
Property: declaredConstructors
Property: declaredFields
Property: declaredMethods
Property: declaringClass
Property: enclosingClass
Property: enclosingConstructor
Property: enclosingMethod
Property: enum
Property: enumConstants
Property: fields
Property: genericInterfaces
Property: genericSuperclass
Property: interface
Property: interfaces
Property: localClass
Property: memberClass
Property: methods
Property: modifiers
Property: module
Property: name
Property: nestHost
Property: nestMembers
Property: package
Property: packageName
Property: primitive
Property: protectionDomain
Property: signers
Property: simpleName
Property: superclass
Property: synthetic
Property: typeName
Property: typeParameters

Кроме того, сравните различия в информации, полученной с помощью Introspector.getBeanInfo(Class.class) в разных версиях JDK: выше вывод для jdk-11, ниже вывод для JDK8:```text jdk8: Property: annotatedInterfaces Property: annotatedSuperclass Property: annotation Property: annotations Property: anonymousClass Property: array Property: canonicalName Property: class Property: classLoader Property: classes Property: componentType Property: constructors Property: declaredAnnotations Property: declaredClasses Property: declaredConstructors Property: declaredFields Property: declaredMethods Property: declaringClass Property: enclosingClass Property: enclosingConstructor Property: enclosingMethod Property: enum Property: enumConstants Property: fields Property: genericInterfaces Property: genericSuperclass Property: interface Property: interfaces Property: localClass Property: memberClass Property: methods Property: modifiers Property: name Property: package Property: primitive Property: protectionDomain Property: signers Property: simpleName Property: superclass Property: synthetic Property: typeName Property: typeParameters

C```text
Property: annotatedInterfaces
Property: annotatedSuperclass
Property: annotation
Property: annotations
Property: anonymousClass
Property: array
Property: canonicalName
Property: class
Property: classLoader
Property: classes
Property: componentType
Property: constructors
Property: declaredAnnotations
Property: declaredClasses
Property: declaredConstructors
Property: declaredFields
Property: declaredMethods
Property: declaringClass
Property: enclosingClass
Property: enclosingConstructor
Property: enclosingMethod
Property: enum
Property: enumConstants
Property: fields
Property: genericInterfaces
Property: genericSuperclass
Property: interface
Property: interfaces
Property: localClass
Property: memberClass
Property: methods
Property: modifiers
Property: module
Property: name
Property: package
Property: packageName
Property: primitive
Property: protectionDomain
Property: signers
Property: simpleName
Property: superclass
Property: synthetic
Property: typeName
Property: typeParameters

По сравнению с JDK8, в JDK9 появилось два дополнительных атрибута: module и packageName. А в JDK11, помимо атрибутов module и packageName, есть еще два атрибута: nestHost и nestMembers.

Скачать инструмент