Project Hyphae
Search

SpringShell-Break 2022

Share This Post

VMWare announced their Spring Framework, in the right configuration, is vulnerable to Remote Code Execution. Spring MVC (Model-View-Controller) or Spring WebFlux applications running on JDK9+ may be vulnerable to RCE via data binding. This vulnerability currently has only been confirmed on applications running on Tomcat as a WAR deployment (this has likely changed at time of publish, as more applications are being noted as vulnerable, both VMware and Cisco have announced vulnerabilities). The default deployment as a Spring Boot executable jar is not vulnerable though. VMWare has stated that there may be other ways to exploit the vulnerability that just haven’t been identified yet. This vulnerability affects all Spring Framework versions 5.3.0-5.3.17, 5.2.0-5.2.17, and even older unsupported versions.

VMWare CVE-2022-22965: https://tanzu.vmware.com/security/cve-2022-22965

To mitigate the vulnerability you should upgrade to 5.3.18+(for 5.3.X users) or 5.2.20+(for 5.2.X users). If you are running applications that cannot upgrade to these versions, please check the mitigation steps that were provided in the Suggested Workarounds section on the RCE-Early-Announcement blog post from spring.

Spring RCE Early Announcement: https://spring.io/blog/2022/03/31/spring-framework-rce-early-announcement



Reach out to our incident response team for help

More To Explore

Information Security News 4-22-2024

Cisco Duo Warns Third-Party Data Breach Exposed SMS MFA Logs Article Link: https://www.bleepingcomputer.com/news/security/cisco-duo-warns-third-party-data-breach-exposed-sms-mfa-logs/ Notorious Russian Hacking Unit Linked to Breach of Texas Water Facility Article

Information Security News 4-15-2024

Roku Disclosed a Security Incident Impacting 576,000 Accounts Article Link: https://securityaffairs.com/161765/data-breach/roku-second-data-breach.html FBI Warns of Massive Wave of Road Toll SMS Phishing Attacks Article Link: https://www.bleepingcomputer.com/news/security/fbi-warns-of-massive-wave-of-road-toll-sms-phishing-attacks/

Do You Want to Shore Up Your Defenses?

We're opening our first round of threat hunting engagements to 100 organizations. Sign up or join the wait list here.