4 ms·
A Technical Analysis of How Spring4Shell (CVE-2022-22965) Works
- cws 5y agoThis is about CVE-2022-22965. Maybe I’ll edit the title to reflect that.
- ajdenver 5y agogood idea.
- PeekPoke 5y agoThat's a good technical write-up. I wonder how much of an issue this CVE will be compared to Log4Shell....
- cws 5y agoDepends a lot on how many Spring apps out there have the prereqs to be vulnerable. The widespread nature of Log4Shell is what made it “worse” than other RCE vulns. I don’t have a sense of how many vulnerable instances of this one might be out there but the number could be enormous.
- ajdenver 5y agoI've been told it can be hard to know if vendor-built apps in your environment are using Spring. What are some apps built on this platform?
- rpple 5y agoWhether or not this turns out to have the same blast radius and Log4Shell, it has certainly captured a lot of attention. Lots and lots of folks using Tomcat...
- alipitch 4y agoAre there any data binding libraries (deserialization, marshaling, pickling libraries) that do not have the class of weaknesses as the two CVEs (CVE-2022-22965, CVE-2010-1622)? If there are any for Java, can they be used with Spring Boot (Spring Framework)? Maybe there are some for in another programming language?