SpringShell-Break 2022

Share This Post

VMWare announced their Spring Framework, in the right configuration, is vulnerable to Remote Code Execution. Spring MVC (Model-View-Controller) or Spring WebFlux applications running on JDK9+ may be vulnerable to RCE via data binding. This vulnerability currently has only been confirmed on applications running on Tomcat as a WAR deployment (this has likely changed at time of publish, as more applications are being noted as vulnerable, both VMware and Cisco have announced vulnerabilities). The default deployment as a Spring Boot executable jar is not vulnerable though. VMWare has stated that there may be other ways to exploit the vulnerability that just haven’t been identified yet. This vulnerability affects all Spring Framework versions 5.3.0-5.3.17, 5.2.0-5.2.17, and even older unsupported versions.

VMWare CVE-2022-22965: https://tanzu.vmware.com/security/cve-2022-22965

To mitigate the vulnerability you should upgrade to 5.3.18+(for 5.3.X users) or 5.2.20+(for 5.2.X users). If you are running applications that cannot upgrade to these versions, please check the mitigation steps that were provided in the Suggested Workarounds section on the RCE-Early-Announcement blog post from spring.

Spring RCE Early Announcement: https://spring.io/blog/2022/03/31/spring-framework-rce-early-announcement



Reach out to our incident response team for help

More To Explore

Information Security News – 5/12/2025

Microsoft Sets Passkeys Default for New Accounts Article Link: https://thehackernews.com/2025/05/microsoft-sets-passkeys-default-for-new.html Accenture: What We Learned When Our CEO Got Deepfaked Article Link: https://www.computing.co.uk/event/2025/accenture-what-we-learned-when-our-ceo-got-deepfaked Ghost Students Creating

Information Security News – 5/5/2025

Cloudflare Sees a Big Jump in DDoS Attacks Article Link: https://www.bleepingcomputer.com/news/security/cloudflare-mitigates-record-number-of-ddos-attacks-in-2025/ Bring Your Own Computer Trend Gives Cyber Pros Chills, Yet It’s Here to Stay

Do You Want to Shore Up Your Defenses?

We're opening our first round of threat hunting engagements to 100 organizations. Sign up or join the wait list here.