logo

Important Updates on Spring4Shell Vulnerability

ID: aaf11a95-1da8-53d6-a82e-ff365d016a04

STIX ID: report--aaf11a95-1da8-53d6-a82e-ff365d016a04

Feed Name: Arctic Wolf Blog

Threat Score
75/100

Date Published: 2022-04-03

Date Updated: 2026-04-26

...
...

Arctic Wolf describes the Spring4Shell (CVE-2022-22965) remote code execution vulnerability affecting Spring Framework versions (notably 5.3.0–5.3.17 and 5.2.0–5.2.19) when running JDK 9+, deployed as WAR on Apache Tomcat, confirms PoC exploitability, releases an open-source Spring4Shell Deep Scan detection tool, and provides explicit upgrade and patching recommendations for Spring Framework and Spring Cloud Function.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.