Spring Framework RCE Vulnerability CVE-2022-22965 Exploited in the Wild
ID: 8bf5e305-0746-58b5-bfda-4769e5192303
STIX ID: report--8bf5e305-0746-58b5-bfda-4769e5192303
Feed Name: ThreatCluster
Threat Score
A critical zero-day RCE (CVE-2022-22965, "Spring4Shell") impacting Spring MVC and Spring WebFlux on JDK 9+ when deployed as a WAR on Tomcat was disclosed on 2022-03-30 (CVSS 9.8). Vendors reported limited in‑the‑wild exploitation; Spring released fixes (5.3.18 / 5.2.20+) and provided workarounds for users unable to upgrade immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
