Spring Framework RCE Vulnerability CVE-2022-22965 Exploited in the Wild
ID: 652e54f3-7352-5ae0-b059-3f9be53a2226
STIX ID: report--652e54f3-7352-5ae0-b059-3f9be53a2226
Feed Name: ThreatCluster
On March 30, 2022 a zero-day remote code execution vulnerability in the Spring Framework (Spring4Shell, CVE-2022-22965) was disclosed. The flaw (CVSS 9.8) affects Spring MVC and Spring WebFlux apps running on JDK 9+ when deployed as a WAR on Tomcat; Spring Boot executable jars are not affected. Multiple vendors reported limited in-the-wild exploitation; Spring released patches on April 1, 2022 (upgrade to Spring Framework 5.3.18 or 5.2.20+) and provided workarounds for those unable to upgrade immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
