spring.io Spring Framework RCE Vulnerability CVE-2022-22965 Exploited in the Wild
Article Content
- •CVE-2022-22965 is a critical RCE vulnerability in Spring Framework with a CVSS score of 9.8.
- •Exploitation requires applications to run on Tomcat as a WAR deployment; Spring Boot executable jars are not affected.
- •Users are advised to upgrade to Spring Framework 5.3.18 or 5.2.20+ to mitigate the vulnerability.
On March 30, 2022, a zero-day remote code execution vulnerability in the Spring Framework, dubbed 'Spring4Shell' and assigned CVE-2022-22965, was disclosed. This vulnerability affects Spring MVC and Spring WebFlux applications running on JDK 9+ and requires deployment on Tomcat as a WAR file. Multiple security vendors, including Rapid7, confirmed in-the-wild exploitation attempts, although activity appears limited to a small number of actors. The CVSS score for this vulnerability is 9.8, indicating critical severity. Spring released a fix on April 1, 2022, and users are urged to upgrade to Spring Framework versions 5.3.18 or 5.2.20 or greater. Workarounds are available for those unable to upgrade immediately. The vulnerability was reported by researchers from AntGroup FG and Praetorian.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track CVE-2022-22965 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…