spring.io
Spring Framework RCE Vulnerability CVE-2022-22965 Exploited in the Wild
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
On March 30, 2022, a zero-day remote code execution vulnerability in the Spring Framework, dubbed 'Spring4Shell' and assigned CVE-2022-22965, was disclosed. This vulnerability affects Spring MVC and Spring WebFlux applications running on JDK 9+ and requires deployment on Tomcat as a WAR file. Multiple security vendors, including Rapid7, confirmed in-the-wild exploitation attempts, although activity appears limited to a small number of actors. The CVSS score for this vulnerability is 9.8, indicating critical severity. Spring released a fix on April 1, 2022, and users are urged to upgrade to Spring Framework versions 5.3.18 or 5.2.20 or greater. Workarounds are available for those unable to upgrade immediately. The vulnerability was reported by researchers from AntGroup FG and Praetorian.
Key Points: • CVE-2022-22965 is a critical RCE vulnerability in Spring Framework with a CVSS score of 9.8. • Exploitation requires applications to run on Tomcat as a WAR deployment; Spring Boot executable jars are not affected. • Users are advised to upgrade to Spring Framework 5.3.18 or 5.2.20+ to mitigate the vulnerability.