logo

Critical Guidance on the CVE 2022-22965 (Spring4Shell) Vulnerability

ID: 88fbd1d0-22d2-54b0-a73f-698e044004ec

STIX ID: report--88fbd1d0-22d2-54b0-a73f-698e044004ec

Feed Name: TrustedSec blog

Threat Score
75/100

Date Published: 2025-04-25

Date Updated: 2026-05-01

...
...

This report details the Spring4Shell RCE (CVE-2022-22965) affecting Spring Framework applications running on JDK9+ with Apache Tomcat packaged as WARs, lists affected versions and vendor advisories, recommends upgrading to patched Spring/Spring Boot versions or applying mitigations (WAF rules and DataBinder denylist), and provides detection resources (YARA, scanners, OWASP Dependency Check) and proof-of-concept links. It also notes a separate related issue (CVE-2022-22963) and aggregates community resources and guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.