Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
spring-RCE-CVE-2022-22965 — 针对 CVE-2022-22965 的教育性分析与概念验证利用,该漏洞是 Spring MVC/WebFlux 在 JDK 9+ 环境下通过数据绑定实现的远程代码执行漏洞,影响使用 Tomcat WAR 部署的应用。 | Kitploit
工具/GitHubGitHub/enokiy/spring-rce-cve-2022-22965
漏洞分析代码分析漏洞利用Web应用程序漏洞利用学习与教育
GitHubenokiy/spring-rce-cve-2022-22965

spring-RCE-CVE-2022-22965

针对 CVE-2022-22965 的教育性分析与概念验证利用,该漏洞是 Spring MVC/WebFlux 在 JDK 9+ 环境下通过数据绑定实现的远程代码执行漏洞,影响使用 Tomcat WAR 部署的应用。

查看仓库
124年前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

漏洞简介

最近spring爆出重磅级CVE漏洞,cve信息显示"A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.(在 JDK 9+ 上运行的 Spring MVC 或 Spring WebFlux应用程序可能容易受到通过数据绑定的远程代码执行 (RCE) 的攻击。具体的利用需要应用程序作为war包部署在 Tomcat上运行。 如果应用程序部署为Spring Boot可执行jar,即默认值,则它不易受到攻击。但是,该漏洞的性质更为普遍,可能还有其他方法可以利用它)"。本次分析通过复现该CVE学习漏洞原理。

java Bean API

看springmvc的参数绑定原理之前,我们先来看下java Bean相关的一些API。

  • java Bean:实际上是一种规范,当一个类满足这个规范,这个类就能被其它特定的类调用。一个类被当作java Bean使用时,该类包含一组私有属性,通过public的 get/is()或set()方法对属性进行读写操作。
  • Introspector(内省): The Introspector class provides a standard way for tools to learn about the properties, events, and methods supported by a target Java Bean. For each of those three kinds of information, the Introspector will separately analyze the bean's class and superclasses looking for either explicit or implicit information and use that information to build a BeanInfo object that comprehensively describes the target bean.(Java对Java Bean类的属性、事件和方法提供的缺省处理方式。比如,查找某个bean类的属性/方法时,如果在当前bean类中没找到这个属性,则向bean类的父类中查找等约定。)
  • BeanInfo:Introspect on a Java Bean and learn about all its properties, exposed methods, and events.If the BeanInfo class for a Java Bean has been previously Introspected then the BeanInfo class is retrieved from the BeanInfo cache.(对 Java Bean 进行内省并了解其所有属性、公开的方法和事件。如果Java Bean 的 BeanInfo 类先前已被内省,则从 BeanInfo 缓存中检索BeanInfo类。)
  • PropertyDescriptor:用于描述java Bean通过一组accessor methods暴露的属性。

声明如下的java bean类:

public class User {
    private String name;

    public User() {
    }
    public void setName(String name) {
        this.name = name;
    }
    public String getName() {
        return this.name;
    }
    public int getAge() {
        return 18;
    }
}

用如下的测试代码来看下Introspector.getBeanInfo获取到的信息:

@Test
    public  void testIntrospector() throws IntrospectionException {
        BeanInfo beanInfo = Introspector.getBeanInfo(User.class);
        for (PropertyDescriptor pdesc:beanInfo.getPropertyDescriptors()){
            System.out.println("Property: " + pdesc.getName() + ",Class:" + pdesc.getPropertyType());
        }
//        for (MethodDescriptor md:beanInfo.getMethodDescriptors()) {
//            System.out.println("Method: " + md.getName());
//        }
    }

output:

Property: age,Class:int
Property: class,Class:class java.lang.Class
Property: name,Class:class java.lang.String

除了在预料之内的age和那么之外,还有一个class属性,类名是Class,如果再继续调用Introspector.getBeanInfo(Class.class)可以获取到classLoader等更多的信息:

Property: annotatedInterfaces
Property: annotatedSuperclass
Property: annotation
Property: annotations
Property: anonymousClass
Property: array
Property: canonicalName
Property: class
Property: classLoader
Property: classes
Property: componentType
Property: constructors
Property: declaredAnnotations
Property: declaredClasses
Property: declaredConstructors
Property: declaredFields
Property: declaredMethods
Property: declaringClass
Property: enclosingClass
Property: enclosingConstructor
Property: enclosingMethod
Property: enum
Property: enumConstants
Property: fields
Property: genericInterfaces
Property: genericSuperclass
Property: interface
Property: interfaces
Property: localClass
Property: memberClass
Property: methods
Property: modifiers
Property: module
Property: name
Property: nestHost
Property: nestMembers
Property: package
Property: packageName
Property: primitive
Property: protectionDomain
Property: signers
Property: simpleName
Property: superclass
Property: synthetic
Property: typeName
Property: typeParameters

另外再对比下不同JDK版本下Introspector.getBeanInfo(Class.class)获取到的信息的区别,上面的是jdk-11下的输出,下面的是JDK8下的输出:

Property: annotatedInterfaces
Property: annotatedSuperclass
Property: annotation
Property: annotations
Property: anonymousClass
Property: array
Property: canonicalName
Property: class
Property: classLoader
Property: classes
Property: componentType
Property: constructors
Property: declaredAnnotations
Property: declaredClasses
Property: declaredConstructors
Property: declaredFields
Property: declaredMethods
Property: declaringClass
Property: enclosingClass
Property: enclosingConstructor
Property: enclosingMethod
Property: enum
Property: enumConstants
Property: fields
Property: genericInterfaces
Property: genericSuperclass
Property: interface
Property: interfaces
Property: localClass
Property: memberClass
Property: methods
Property: modifiers
Property: name
Property: package
Property: primitive
Property: protectionDomain
Property: signers
Property: simpleName
Property: superclass
Property: synthetic
Property: typeName
Property: typeParameters
Property: annotatedInterfaces
Property: annotatedSuperclass
Property: annotation
Property: annotations
Property: anonymousClass
Property: array
Property: canonicalName
Property: class
Property: classLoader
Property: classes
Property: componentType
Property: constructors
Property: declaredAnnotations
Property: declaredClasses
Property: declaredConstructors
Property: declaredFields
Property: declaredMethods
Property: declaringClass
Property: enclosingClass
Property: enclosingConstructor
Property: enclosingMethod
Property: enum
Property: enumConstants
Property: fields
Property: genericInterfaces
Property: genericSuperclass
Property: interface
Property: interfaces
Property: localClass
Property: memberClass
Property: methods
Property: modifiers
Property: module
Property: name
Property: package
Property: packageName
Property: primitive
Property: protectionDomain
Property: signers
Property: simpleName
Property: superclass
Property: synthetic
Property: typeName
Property: typeParameters

jdk9相比JDK8多出来两个属性module和packageName,而JDK11上除了module和packageName属性之外还有另外两个属性nestHost和nestMembers。

data binding数据绑定

web类框架中的参数绑定过程,通俗点来说就是,框架把http请求中的字符串形式的参数转换成服务端真正需要的类型,以spring MVC为例: 定义两个Bean 类User和UserInfo:

public class UserInfo {
    public User getUser() {
        return user;
    }

    public void setUser(User user) {
        this.user = user;
    }

    public String getPassword() {
        return password;
    }

    public void setPassword(String password) {
        this.password = password;
    }

    private User user;
    private String password;

    @Override
    public String toString() {
        return "UserInfo{" +
                "user=" + user +
                ", password='" + password + '\'' +
                '}';
    }
}

用如下的controller作为测试:

import org.springframework.web.bind.annotation.RequestMapping;
import org.springframework.web.bind.annotation.RestController;

@RestController
public class DemoController {
    public DemoController() {
    }

    @RequestMapping({"/test"})
    public String test(User u) {
        System.out.println("access!");
        return "home";
    }

    @RequestMapping({"/get-user-info"})
    public String getUserInfo(UserInfo userInfo) {
        System.out.println("Name:"  + userInfo.getUser().getName());
        System.out.println("Age:"  + userInfo.getUser().getAge());
        System.out.println("password:" + userInfo.getPassword());
        System.out.println("classLoader:" + userInfo.getClass().getClassLoader());

        return userInfo.toString();
    }
}

当我们访问/get-user-info?password=password&user.name=enokiy时,框架会自动的实例化UserInfo类,并且把对应的值绑定到对应的属性上(通过user.name可以嵌套访问userInfo.user.name属性):

下载工具