Toutes les vulnérabilités
CRITICALInfraexploited in the wild

CVE-2022-22965

Spring · Spring Framework (spring-beans)

Résumé

A remote code execution flaw in the Spring Framework's data-binding mechanism. On JDK 9 and later, an unauthenticated attacker can manipulate request parameters to access the ClassLoader and write a malicious JSP web shell to disk, achieving RCE. Exploitation specifically targets Spring MVC and WebFlux applications deployed as WAR files on Apache Tomcat. It was mass-exploited within days of disclosure to deploy cryptocurrency miners and the Mirai botnet.

Références

Vulnérabilités liées

Tout Infra →