CVE-2022-22963
published 2022-04-01CVE-2022-22963: In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a…
PriorityP197critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2022-09-15
Exploited in the wild
EPSS
99.94%
100.0th percentile
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
Affected
71 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | banking_branch | — | — |
| oracle | banking_cash_management | — | — |
| oracle | banking_corporate_lending_process_management | — | — |
| oracle | banking_credit_facilities_process_management | — | — |
| oracle | banking_electronic_data_exchange_for_corporates | — | — |
| oracle | banking_liquidity_management | — | — |
| oracle | banking_liquidity_management | — | — |
| oracle | banking_origination | — | — |
| oracle | banking_supply_chain_finance | — | — |
| oracle | banking_trade_finance_process_management | — | — |
| oracle | banking_virtual_account_management | — | — |
| oracle | communications_cloud_native_core_automated_test_suite | — | — |
| oracle | communications_cloud_native_core_automated_test_suite | — | — |
| oracle | communications_cloud_native_core_console | — | — |
| oracle | communications_cloud_native_core_console | — | — |
| oracle | communications_cloud_native_core_network_exposure_function | — | — |
| oracle | communications_cloud_native_core_network_function_cloud_native_environment | — | — |
| oracle | communications_cloud_native_core_network_function_cloud_native_environment | — | — |
| oracle | communications_cloud_native_core_network_function_cloud_native_environment | — | — |
| oracle | communications_cloud_native_core_network_repository_function | — | — |
| oracle | communications_cloud_native_core_network_repository_function | — | — |
| oracle | communications_cloud_native_core_network_slice_selection_function | — | — |
| oracle | communications_cloud_native_core_network_slice_selection_function | — | — |
| oracle | communications_cloud_native_core_policy | — | — |
| oracle | communications_cloud_native_core_policy | — | — |
Detection & IOCsextracted from sources · hover to see the quote
snort↗
Snort SIDs: 30790-30793, 59388, and 59416
- →CVE-2022-22963 is only exploitable in applications using Spring Cloud Function routing functionality; focus detection on endpoints that process routing expressions ↗
- →The vulnerability is remotely exploitable without authentication via a specially crafted HTTP request; alert on unauthenticated POST requests to Spring Cloud Function endpoints with routing-expression headers ↗
- →CVE-2022-22963 affects Spring Cloud Function versions 3.1.6, 3.2.2 and older; detect vulnerable version strings in deployed JAR manifests or dependency trees ↗
- ·CVE-2022-22963 is only exploitable when the Spring Cloud Function application uses routing functionality; applications not using routing are not affected ↗
- ·Most software dependent on the Spring Cloud Function library runs on short-lived FaaS/Serverless instances, limiting practical exploitation impact in many environments ↗
- ·The SpEL payload is evaluated by SimpleEvaluationContext; detection rules should account for obfuscated or variant SpEL expressions targeting the routing-expression header ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_cisco9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-09-04·CVSS 6.0
CVE-2010-1622 [MEDIUM] PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2010-1622, CVE-2015-7552, CVE-2018-16840, CVE-2019-7639, CVE-2020-17049, CVE-2020-7774, CVE-2021-0131, CVE-2021-0132, CVE-2021-0133, CVE-2021-0134, CVE-2021-4044, CVE-2021-4160, CVE-2021-41773, CVE-2022-1343, CVE-2022-21449, CVE-2022-2274, CVE-2022-22963, CVE-2022-22965, CVE-2022-24697, CVE-2022-32207, CVE-2022-3358, CVE-2022-3996, CVE-2022-40664, CVE-2022-44792, CVE-2022-44793, CVE-2023-1255, CVE-2023-22809, CVE-2023-23919, CVE-2023-3341, CVE-2023-4236, CVE-2023-4863, CVE-2023-51767
Affected products: PAN-OS
Palo Alto
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-09-04·CVSS 6.0
CVE-2022-22965 [MEDIUM] PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2010-1622, CVE-2015-7552, CVE-2018-16840, CVE-2019-7639, CVE-2020-17049, CVE-2020-7774, CVE-2021-0131, CVE-2021-0132, CVE-2021-0133, CVE-2021-0134, CVE-2021-4044, CVE-2021-4160, CVE-2021-41773, CVE-2022-1343, CVE-2022-21449, CVE-2022-2274, CVE-2022-22963, CVE-2022-22965, CVE-2022-24697, CVE-2022-32207, CVE-2022-3358, CVE-2022-3996, CVE-2022-40664, CVE-2022-44792, CVE-2022-44793, CVE-2023-1255, CVE-2023-22809, CVE-2023-23919, CVE-2023-3341, CVE-2023-4236, CVE-2023-4863, CVE-2023-51767
Affected products: PAN-OS
CISA
VMware Tanzu Spring Cloud Function Remote Code Execution Vulnerability
cisa·2022-08-25·CVSS 9.8
CVE-2022-22963 [CRITICAL] CWE-94 VMware Tanzu Spring Cloud Function Remote Code Execution Vulnerability
Vulnerability: VMware Tanzu Spring Cloud Function Remote Code Execution Vulnerability
Affected: VMware Tanzu Spring Cloud
When using routing functionality in VMware Tanzu's Spring Cloud Function, it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
Required Action: Apply updates per vendor instructions.
Notes: https://tanzu.vmware.com/security/cve-2022-22963; https://nvd.nist.gov/vuln/detail/CVE-2022-22963
Remediation Due Date: 2022-09-15
Oracle
Oracle Oracle Communications Risk Matrix: DBTier (Spring Cloud Function) — CVE-2022-22963
vendor_oracle·2022-07-15·CVSS 9.8
CVE-2022-22963 [CRITICAL] Oracle Oracle Communications Risk Matrix: DBTier (Spring Cloud Function) — CVE-2022-22963
Oracle Oracle Communications Risk Matrix: DBTier (Spring Cloud Function) vulnerability
CVE: CVE-2022-22963
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
Cisco
Vulnerability in Spring Cloud Function Framework Affecting Cisco Products: March 2022
vendor_cisco·2022-04-01·CVSS 9.8
CVE-2022-22963 [CRITICAL] CWE-497 Vulnerability in Spring Cloud Function Framework Affecting Cisco Products: March 2022
Vulnerability in Spring Cloud Function Framework Affecting Cisco Products: March 2022
On March 29, 2022, the following critical vulnerability in the Spring Cloud Function Framework affecting releases 3.1.6, 3.2.2, and older unsupported releases was disclosed:
CVE-2022-22963: Remote code execution in Spring Cloud Function by malicious Spring Expression
For a description of this vulnerability, see VMware Spring Framework Security Vulnerability Report.
Cisco's Response to This Vulnerability
Cisco accessed all products for impact from CVE-2022-22963. To help detect exploitation of this vulnerability, Cisco has released Snort rules at the following location: Talos Rule SID 59388
This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecu
Palo Alto
Informational: Impact of Spring Vulnerabilities CVE-2022-22963 and CVE-2022-22965
vendor_paloalto·2022-03-31·CVSS 9.8
CVE-2022-22963 [CRITICAL] CWE-497 Informational: Impact of Spring Vulnerabilities CVE-2022-22963 and CVE-2022-22965
Informational: Impact of Spring Vulnerabilities CVE-2022-22963 and CVE-2022-22965
The Palo Alto Networks Product Security Assurance team has completed its evaluation of the Spring Cloud Function vulnerability CVE-2022-22963 and Spring Core vulnerability CVE-2022-22965 for all products and services. All Palo Alto Networks cloud services with possible impact have been mitigated and remediated.
The following products and services are not impacted by these Spring vulnerabilities: AutoFocus, Bridgecrew, Cortex Data Lake, Cortex XDR agent, Cortex Xpanse, Cortex XSOAR, Enterprise Data Loss Prevention, Exact Data Matching (EDM) CLI, Expanse, Expedition Migration Tool, GlobalProtect app, IoT Security, Okyo Garde, Palo Alto Networks App for Splunk, PAN-OS hardware and virtual firewalls and Panoram
Red Hat
spring-cloud-function: Remote code execution by malicious Spring Expression
vendor_redhat·2022-03-29·CVSS 9.8
CVE-2022-22963 [CRITICAL] CWE-94 spring-cloud-function: Remote code execution by malicious Spring Expression
spring-cloud-function: Remote code execution by malicious Spring Expression
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
A flaw was found in Spring Cloud Function via the spring.cloud.function.routing-expression header that is modified by the attacker to contain malicious expression language code. The attacker is able to call functions that should not normally be accessible, including runtime exec calls.
Mitigation: Affected customers should update immediately as soon as patched software is available. There are no other mitigations available at this time.
Package:
Cisco
Vulnerability in Spring Cloud Function Framework Affecting Cisco Products: March 2022
vendor_cisco·CVSS 3.0
CVE-2022-22963 Vulnerability in Spring Cloud Function Framework Affecting Cisco Products: March 2022
CVE-2022-22963: Vulnerability in Spring Cloud Function Framework Affecting Cisco Products: March 2022
On March 29, 2022, the following critical vulnerability in the Spring Cloud Function Framework affecting releases 3.1.6, 3.2.2, and older unsupported releases was disclosed: CVE-2022-22963: Remote code execution in Spring Cloud Function by malicious Spring Expression For a description of this vulnerability, see VMware Spring Framework Security Vulnerability Report . Cisco's Response to This Vulnerability Cisco accessed all products for impact from CVE-2022-22963. To help detect exploitation of this vulnerability, Cisco has released Snort rules at the following location: Talos Rule SID 59388 This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/co
GHSA
Spring Cloud Function Code Injection with a specially crafted SpEL as a routing expression
ghsa·2022-04-03
CVE-2022-22963 [CRITICAL] CWE-917 Spring Cloud Function Code Injection with a specially crafted SpEL as a routing expression
Spring Cloud Function Code Injection with a specially crafted SpEL as a routing expression
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
OSV
Spring Cloud Function Code Injection with a specially crafted SpEL as a routing expression
osv·2022-04-03
CVE-2022-22963 [CRITICAL] Spring Cloud Function Code Injection with a specially crafted SpEL as a routing expression
Spring Cloud Function Code Injection with a specially crafted SpEL as a routing expression
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
VulnCheck
VMware Tanzu Spring Cloud Function Remote Code Execution Vulnerability
vulncheck·2022·CVSS 9.8
CVE-2022-22963 [CRITICAL] CWE-94 VMware Tanzu Spring Cloud Function Remote Code Execution Vulnerability
VMware Tanzu Spring Cloud Function Remote Code Execution Vulnerability
When using routing functionality in VMware Tanzu's Spring Cloud Function, it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
Affected: VMware Spring Cloud
Required Action: Apply updates per vendor instructions.
Exploitation References: https://unit42.paloaltonetworks.com/recent-exploits-network-security-trends/; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://web-assets.esetstatic.com/wls/2023/07/eset_threat_report_h12023.pdf; https://cisa.gov/news-events/cybersecurity-advisories/aa23-215a; https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2023/11/090
Suricata
ET EXPLOIT Possible Spring Cloud Connector RCE Inbound (CVE-2022-22963)
suricata·2022-03-31·CVSS 9.8
CVE-2022-22963 [CRITICAL] ET EXPLOIT Possible Spring Cloud Connector RCE Inbound (CVE-2022-22963)
ET EXPLOIT Possible Spring Cloud Connector RCE Inbound (CVE-2022-22963)
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Possible Spring Cloud Connector RCE Inbound (CVE-2022-22963)"; flow:established,to_server; http.header; content:"spring.cloud.function.routing-expression|3a|"; fast_pattern; reference:cve,2022-22963; classtype:attempted-admin; sid:2035670; rev:2; metadata:attack_target Server, created_at 2022_03_31, cve CVE_2022_22963, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2024_03_08, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Exploit-DB
Spring Cloud 3.2.2 - Remote Command Execution (RCE)
exploitdb·2023-07-11·CVSS 9.8
CVE-2022-22963 [CRITICAL] Spring Cloud 3.2.2 - Remote Command Execution (RCE)
Spring Cloud 3.2.2 - Remote Command Execution (RCE)
---
# Exploit Title: Spring Cloud 3.2.2 - Remote Command Execution (RCE)
# Date: 07/07/2023
# Exploit Author: GatoGamer1155, 0bfxgh0st
# Vendor Homepage: https://spring.io/projects/spring-cloud-function/
# Description: Exploit to execute commands exploiting CVE-2022-22963
# Software Link: https://spring.io/projects/spring-cloud-function
# CVE: CVE-2022-22963
import requests, argparse, json
parser = argparse.ArgumentParser()
parser.add_argument("--url", type=str, help="http://172.17.0.2:8080/functionRouter", required=True)
parser.add_argument("--command", type=str, help="ping -c1 172.17.0.1", required=True)
args = parser.parse_args()
print("\n\033[0;37m[\033[0;33m!\033[0;37m] It is possible that the output of the injected command is n
Metasploit
Spring Cloud Function SpEL Injection
metasploit
Spring Cloud Function SpEL Injection
Spring Cloud Function SpEL Injection
Spring Cloud Function versions prior to 3.1.7 and 3.2.3 are vulnerable to remote code execution due to using an unsafe evaluation context with user-provided queries. By crafting a request to the application and setting the spring.cloud.function.routing-expression header, an unauthenticated attacker can gain remote code execution. Both patched and unpatched servers will respond with a 500 server error and a JSON encoded message.
Nuclei
Spring Cloud - Remote Code Execution
nuclei·CVSS 9.8
CVE-2022-22963 [CRITICAL] Spring Cloud - Remote Code Execution
Spring Cloud - Remote Code Execution
Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions are susceptible to remote code execution vulnerabilities. When using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
Template:
id: CVE-2022-22963
info:
name: Spring Cloud - Remote Code Execution
author: Mr-xn,Adam Crosser
severity: critical
description: |
Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions are susceptible to remote code execution vulnerabilities. When using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and
Zscaler
Zero Trust for Cloud Architects: Turning Spring4Shell Lessons into Resilient Workload Design | Zscaler
blogs_zscaler·2025-11-04·CVSS 9.8
[CRITICAL] Zero Trust for Cloud Architects: Turning Spring4Shell Lessons into Resilient Workload Design | Zscaler
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Tenable
AA23-215A: 2022's Top Routinely Exploited Vulnerabilities
blogs_tenable·2023-08-03
AA23-215A: 2022's Top Routinely Exploited Vulnerabilities
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
Identify Server-Side Attacks Using Qualys Periscope | Qualys
blogs_qualys·2022-12-01·CVSS 8.8
[HIGH] Identify Server-Side Attacks Using Qualys Periscope | Qualys
#### Table of Contents
- Potential False Positives
- Potential False Negatives
Qualys previously announced the introduction of Qualys Periscope in 2020. This technology allows Qualys Web Application Scanning (WAS) to detect out-of-band vulnerabilities such as server-side request forgery (SSRF). Qualys Periscope provides confirmed detections for additional vulnerabilities, such as Log4j, where it enables rapid development and release of the QID. Occasionally, Qualys receives questions and support cases related to Qualys Periscope. This article will provide more detail on the common questions/situations seen with out-of-band detections.
As of publishing, the vulnerability detections that utilize Qualys Periscope are:
- QID 150055 – OS Command Injection
- QID 150179 – Blind XXE injection
Qualys
Identify Server-Side Attacks Using Qualys Periscope
blogs_qualys·2022-12-01·CVSS 8.8
[HIGH] Identify Server-Side Attacks Using Qualys Periscope
## Table of Contents
Potential False Positives
Potential False Negatives
Qualys previously announced the introduction of Qualys Periscope in 2020. This technology allows Qualys Web Application Scanning (WAS) to detect out-of-band vulnerabilities such as server-side request forgery (SSRF). Qualys Periscope provides confirmed detections for additional vulnerabilities, such as Log4j, where it enables rapid development and release of the QID. Occasionally, Qualys receives questions and support cases related to Qualys Periscope . This article will provide more detail on the common questions/situations seen with out-of-band detections.
As of publishing, the vulnerability detections that utilize Qualys Periscope are:
QID 150055 – OS Command Injection
QID 150179 – Blind XXE injection
QID 15
Unit42
Network Security Trends: Recent Exploits Observed in the Wild Include Remote Code Execution, Cross-Site Scripting and More
blogs_unit42·2022-08-19·CVSS 8.8
CVE-2021-20166 [HIGH] Network Security Trends: Recent Exploits Observed in the Wild Include Remote Code Execution, Cross-Site Scripting and More
Threat Research Center
Trend Reports
Vulnerabilities
## Network Security Trends: Recent Exploits Observed in the Wild Include Remote Code Execution, Cross-Site Scripting and More
Yue Guan
Published: August 19, 2022
Trend Reports
Vulnerabilities
Attack analysis
CVE-2021-20166
CVE-2021-20167
CVE-2021-21881
CVE-2021-24762
CVE-2021-28169
CVE-2021-31589
CVE-2021-39226
CVE-2021-4045
CVE-2021-43711
CVE-2022-21371
CVE-2022-21662
CVE-2022-22536
CVE-2022-22947
CVE-2022-22954
CVE-2022-22963
CVE-2022-22965
CVE-2022-24112
CVE-2022-24260
CVE-2022-25060
CVE-2022-25075
CVE-2022-25134
CVE-2022-27226
CVE-2022-29464
Exploit in the wild
Network security trends
## Executive Summary
Recent observations of exploits used in the wild reveal that attackers have been making use
Unit42
Network Security Trends: Recent Exploits Observed in the Wild Include Remote Code Execution, Cross-Site Scripting and More
blogs_unit42·2022-08-19
Network Security Trends: Recent Exploits Observed in the Wild Include Remote Code Execution, Cross-Site Scripting and More
## Executive Summary
Recent observations of exploits used in the wild reveal that attackers have been making use of newly published remote code execution vulnerabilities in VMware ONE Access and Identity Manager and Spring Cloud Function, Spring MVC and Spring Web Flux, among others. Attackers have also been taking advantage of a cross-site scripting vulnerability in WordPress core, and SQL injection vulnerabilities in VoIPmonitor GUI and other services. In our observations of network security trends, Unit 42 researchers select exploits of the latest published attacks that defenders should know based on the availability of proofs of concept (PoCs), the severity of the vulnerabilities the exploits are based on and the ease of exploitation.
Other insights that could assist defenders includ
Unit42
Top CVEs to Patch: Insights from the 2022 Unit 42 Network Threat Trends Research Report
blogs_unit42·2022-07-21·CVSS 9.8
CVE-2017-5638 [CRITICAL] Top CVEs to Patch: Insights from the 2022 Unit 42 Network Threat Trends Research Report
Threat Research Center
Trend Reports
Vulnerabilities
## Top CVEs to Patch: Insights from the 2022 Unit 42 Network Threat Trends Research Report
Unit 42
Published: July 21, 2022
Trend Reports
Vulnerabilities
Apache Log4j
CVE-2017-5638
CVE-2017-9841
CVE-2018-19986
CVE-2019-02320
CVE-2019-19597
CVE-2019-9082
CVE-2020-14882
CVE-2020-14883
CVE-2020-15505
CVE-2020-15506
CVE-2020-25078
CVE-2020-5902
CVE-2021-21315
CVE-2021-22986
CVE-2021-26855
CVE-2021-31805
CVE-2021-34473
CVE-2021-35464
CVE-2021-38647
CVE-2021-40438
CVE-2021-40539
CVE-2021-41773
CVE-2021-42013
CVE-2021-44228
CVE-2021-45046
CVE-2022-22963
CVE-2022-22965
Network security trends
Unit 42 Network Threat Trends Research Report
## Executive Summary
Tens of thousands of vulnerabilities are repo
Unit42
Top CVEs to Patch: Insights from the 2022 Unit 42 Network Threat Trends Research Report
blogs_unit42·2022-07-21·CVSS 9.8
[CRITICAL] Top CVEs to Patch: Insights from the 2022 Unit 42 Network Threat Trends Research Report
## Executive Summary
Tens of thousands of vulnerabilities are reported every year, but not all are used by threat actors in real-world attacks. There are many reasons for this: a proof of concept (PoC) may not be available for attackers to weaponize, it may be too difficult to exploit the vulnerability, there may be a lack of accessible vulnerable software on the internet, or attackers may simply deem a vulnerability not worth exploiting due to low impact. Real-world defenders need real-world data on which vulnerabilities attackers are choosing to exploit – and where to focus protections.
In the 2022 Unit 42 Network Threat Trends Research Report, we’ve used data captured by the Palo Alto Networks Advanced Threat Prevention security service on Next-Generation Firewall and Prisma SASE from
Trendmicro
CVE-2022-22965 Analyzing the Exploitation of Spring4Shell Vulnerability in Weaponizing and Executing the Mirai Botnet Malware
blogs_trendmicro·2022-04-08·CVSS 9.8
CVE-2022-22965 [CRITICAL] CVE-2022-22965 Analyzing the Exploitation of Spring4Shell Vulnerability in Weaponizing and Executing the Mirai Botnet Malware
## CVE-2022-22965: Analyzing the Exploitation of Spring4Shell Vulnerability in Weaponizing and Executing the Mirai Botnet Malware
We discovered active exploitation of a vulnerability in the Spring Framework designated as CVE-2022-22965 that allows malicious actors to download the Mirai botnet malware.
By: Deep Patel, Nitesh Surana, Ashish Verma Apr 08, 2022 Read time: ( words)
Save to Folio
Trend Micro Threat Research observed active exploitation of the Spring4Shell vulnerability assigned as CVE-2022-22965 , which allows malicious actors to weaponize and execute the Mirai botnet malware . The exploitation allows threat actors to download the Mirai sample to the “/tmp” folder and execute them after permission change using “chmod”.
We began seeing malicious activities at the start of Ap
Trendmicro
CVE-2022-22965 Analyzing the Exploitation of Spring4Shell Vulnerability in Weaponizing and Executing the Mirai Botnet Malware
blogs_trendmicro·2022-04-08·CVSS 9.8
CVE-2022-22965 [CRITICAL] CVE-2022-22965 Analyzing the Exploitation of Spring4Shell Vulnerability in Weaponizing and Executing the Mirai Botnet Malware
## CVE-2022-22965: Analyzing the Exploitation of Spring4Shell Vulnerability in Weaponizing and Executing the Mirai Botnet Malware
We discovered active exploitation of a vulnerability in the Spring Framework designated as CVE-2022-22965 that allows malicious actors to download the Mirai botnet malware.
By: Deep Patel, Ashish Verma Apr 08, 2022 Read time: ( words)
Save to Folio
Trend Micro Threat Research observed active exploitation of the Spring4Shell vulnerability assigned as CVE-2022-22965 , which allows malicious actors to weaponize and execute the Mirai botnet malware . The exploitation allows threat actors to download the Mirai sample to the “/tmp” folder and execute them after permission change using “chmod”.
We began seeing malicious activities at the start of April 2022. We al
Trendmicro
Analyse der Angriffe über die Spring4Shell-Lücke
blogs_trendmicro·2022-04-08·CVSS 9.8
CVE-2022-22965 [CRITICAL] Analyse der Angriffe über die Spring4Shell-Lücke
## CVE-2022-22965: Analyzing the Exploitation of Spring4Shell Vulnerability in Weaponizing and Executing the Mirai Botnet Malware
We discovered active exploitation of a vulnerability in the Spring Framework designated as CVE-2022-22965 that allows malicious actors to download the Mirai botnet malware.
By: Deep Patel, Ashish Verma Apr 08, 2022 Read time: ( words)
Save to Folio
Originalartikel von Deep Patel, Nitesh Surana, Ashish Verma, Threat Researcher
Das Trend Micro Threat Research konnte den aktiven Missbrauch der Spring4Shell-Schwachstelle beobachten. Die Lücke mit der Bezeichung CVE-2022-22965 ermöglicht es Angreifern, Mirai Botnet Malware herunterzuladen und auszuführen. Die ersten bösartigen Aktivitäten verzeichneten wir Anfang April 2022. Wir fanden auch den Malware-Dateiserv
Trendmicro
CVE-2022-22965 Analyzing the Exploitation of Spring4Shell Vulnerability in Weaponizing and Executing the Mirai Botnet Malware
blogs_trendmicro·2022-04-08·CVSS 9.8
CVE-2022-22965 [CRITICAL] CVE-2022-22965 Analyzing the Exploitation of Spring4Shell Vulnerability in Weaponizing and Executing the Mirai Botnet Malware
# CVE-2022-22965: Analyzing the Exploitation of Spring4Shell Vulnerability in Weaponizing and Executing the Mirai Botnet Malware
We discovered active exploitation of a vulnerability in the Spring Framework designated as CVE-2022-22965 that allows malicious actors to download the Mirai botnet malware.
By: Deep Patel, Nitesh Surana, Ashish Verma
Apr 08, 2022
Read time: ( words)
Save to Folio
Trend Micro Threat Research observed active exploitation of the Spring4Shell vulnerability assigned as CVE-2022-22965, which allows malicious actors to weaponize and execute the Mirai botnet malware. The exploitation allows threat actors to download the Mirai sample to the “/tmp” folder and execute them after permission change using “chmod”.
We began seeing malicious activities at the start of Apri
Trendmicro
CVE-2022-22965 Analyzing the Exploitation of Spring4Shell Vulnerability in Weaponizing and Executing the Mirai Botnet Malware
blogs_trendmicro·2022-04-08·CVSS 9.8
CVE-2022-22965 [CRITICAL] CVE-2022-22965 Analyzing the Exploitation of Spring4Shell Vulnerability in Weaponizing and Executing the Mirai Botnet Malware
## CVE-2022-22965: Analyzing the Exploitation of Spring4Shell Vulnerability in Weaponizing and Executing the Mirai Botnet Malware
We discovered active exploitation of a vulnerability in the Spring Framework designated as CVE-2022-22965 that allows malicious actors to download the Mirai botnet malware.
By: Deep Patel, Nitesh Surana, Ashish Verma 2022/04/08 Read time: ( words)
Save to Folio
Trend Micro Threat Research observed active exploitation of the Spring4Shell vulnerability assigned as CVE-2022-22965 , which allows malicious actors to weaponize and execute the Mirai botnet malware . The exploitation allows threat actors to download the Mirai sample to the “/tmp” folder and execute them after permission change using “chmod”.
We began seeing malicious activities at the start of Apri
Trendmicro
CVE-2022-22965 Analyzing the Exploitation of Spring4Shell Vulnerability in Weaponizing and Executing the Mirai Botnet Malware
blogs_trendmicro·2022-04-08·CVSS 9.8
CVE-2022-22965 [CRITICAL] CVE-2022-22965 Analyzing the Exploitation of Spring4Shell Vulnerability in Weaponizing and Executing the Mirai Botnet Malware
# CVE-2022-22965: Analyzing the Exploitation of Spring4Shell Vulnerability in Weaponizing and Executing the Mirai Botnet Malware
We discovered active exploitation of a vulnerability in the Spring Framework designated as CVE-2022-22965 that allows malicious actors to download the Mirai botnet malware.
By: Deep Patel, Nitesh Surana, Ashish Verma
2022/04/08
Read time: ( words)
Save to Folio
Trend Micro Threat Research observed active exploitation of the Spring4Shell vulnerability assigned as CVE-2022-22965, which allows malicious actors to weaponize and execute the Mirai botnet malware. The exploitation allows threat actors to download the Mirai sample to the “/tmp” folder and execute them after permission change using “chmod”.
We began seeing malicious activities at the start of April
Securelist
Spring4Shell (CVE-2022-22965): details and mitigations
blogs_securelist·2022-04-04·CVSS 6.0
CVE-2022-22965 [MEDIUM] Spring4Shell (CVE-2022-22965): details and mitigations
Table of Contents
- CVE-2022-22965 and CVE-2022-22963: technical details
- Mitigations for Spring vulnerabilities exploitation
- Indicators of Compromise
Authors
- AMR
Last week researchers found the critical vulnerability CVE-2022-22965 in Spring – the open source Java framework. Using the vulnerability, an attacker can execute arbitrary code on a remote web server, which makes CVE-2022-22965 a critical threat, given the Spring framework’s popularity. By analogy with the infamous Log4Shell threat, the vulnerability was named Spring4Shell.
## CVE-2022-22965 and CVE-2022-22963: technical details
CVE-2022-22965 (Spring4Shell, SpringShell) is a vulnerability in the Spring Framework that uses data binding functionality to bind data stored within an HTTP request to certain objects used b
Securelist
Spring4Shell (CVE-2022-22965): details and mitigations
blogs_securelist·2022-04-04·CVSS 6.0
CVE-2022-22965 [MEDIUM] Spring4Shell (CVE-2022-22965): details and mitigations
Table of Contents
CVE-2022-22965 and CVE-2022-22963: technical details
Mitigations for Spring vulnerabilities exploitation
Indicators of Compromise
Authors
AMR
Last week researchers found the critical vulnerability CVE-2022-22965 in Spring – the open source Java framework. Using the vulnerability, an attacker can execute arbitrary code on a remote web server, which makes CVE-2022-22965 a critical threat, given the Spring framework’s popularity. By analogy with the infamous Log4Shell threat , the vulnerability was named Spring4Shell.
## CVE-2022-22965 and CVE-2022-22963: technical details
CVE-2022-22965 (Spring4Shell, SpringShell) is a vulnerability in the Spring Framework that uses data binding functionality to bind data stored within an HTTP request to certain objects used by an a
Wiz
Addressing the Spring4Shell and CVE-2022-22963 RCE vulnerabilities in cloud environments | Wiz Blog
blogs_wiz·2022-04-01·CVSS 6.0
CVE-2022-22965 [MEDIUM] Addressing the Spring4Shell and CVE-2022-22963 RCE vulnerabilities in cloud environments | Wiz Blog
Updated April 13th, 2022 to include the latest available information about CVE-2022-22965, further explanation of dependencies in Spring Framework, and data about the prevalence of this vulnerability in cloud environments.
Two critical Remote Code Execution (RCE) vulnerabilities were recently patched in popular Spring Java libraries, and both have generated quite a bit of buzz:
CVE-2022-22965 (Spring Framework RCE via Data Binding on JDK version 9 or higher) –
This vulnerability affects Java software dependent on Spring Framework versions earlier than 5.2.19, and versions 5.3.0 to 5.3.17. Developers must update their software’s dependencies to Spring Framework versions 5.3.18 or 5.2.20, or apply any of multiple workarounds suggested by Spring .
Dubbed “Spring4Shell” (in the same vein a
Wiz
Addressing the Spring4Shell and CVE-2022-22963 RCE vulnerabilities in cloud environments | Wiz Blog
blogs_wiz·2022-04-01·CVSS 6.0
CVE-2022-22963 [MEDIUM] Addressing the Spring4Shell and CVE-2022-22963 RCE vulnerabilities in cloud environments | Wiz Blog
Updated April 13th, 2022 to include the latest available information about CVE-2022-22965, further explanation of dependencies in Spring Framework, and data about the prevalence of this vulnerability in cloud environments.
Two critical Remote Code Execution (RCE) vulnerabilities were recently patched in popular Spring Java libraries, and both have generated quite a bit of buzz:
CVE-2022-22965 (Spring Framework RCE via Data Binding on JDK version 9 or higher) –
- This vulnerability affects Java software dependent on Spring Framework versions earlier than 5.2.19, and versions 5.3.0 to 5.3.17. Developers must update their software’s dependencies to Spring Framework versions 5.3.18 or 5.2.20, or apply any of multiple workarounds suggested by Spring.
- Dubbed “Spring4Shell” (in the same vein
Sentinelone
Spring Cloud Function RCE Vulnerability (CVE-2022-22963)
blogs_sentinelone·2022-04-01·CVSS 9.8
CVE-2022-22963 [CRITICAL] Spring Cloud Function RCE Vulnerability (CVE-2022-22963)
On the 30th of March, 2022, a new Zero-day CVE in Spring Cloud Functions was discovered, named CVE-2022-22963. Spring Cloud Function promotes the implementation of business logic via functions. The vulnerability is remotely exploitable without authentication, i.e., it can be exploited over a network without a username and password.
## What is a Spring Cloud function?
Spring Cloud is an open-source microservice framework. Spring Cloud is a collection of functions useful in building distributed enterprise applications.
Due to the severity of this vulnerability, Sentinelone strongly recommends that customers apply the updates and upgrade the Spring cloud function to the recommended patch Spring Cloud Function 3.2.3 or 3.1.7.
## What is the impact of Spring Cloud vulnerability?
The spring
Sentinelone
Spring Cloud Function RCE Vulnerability (CVE-2022-22963)
blogs_sentinelone·2022-04-01·CVSS 9.8
CVE-2022-22963 [CRITICAL] Spring Cloud Function RCE Vulnerability (CVE-2022-22963)
On the 30th of March, 2022, a new Zero-day CVE in Spring Cloud Functions was discovered, named CVE-2022-22963. Spring Cloud Function promotes the implementation of business logic via functions. The vulnerability is remotely exploitable without authentication, i.e., it can be exploited over a network without a username and password.
## What is a Spring Cloud function?
Spring Cloud is an open-source microservice framework. Spring Cloud is a collection of functions useful in building distributed enterprise applications.
Due to the severity of this vulnerability, Sentinelone strongly recommends that customers apply the updates and upgrade the Spring cloud function to the recommended patch Spring Cloud Function 3.2.3 or 3.1.7.
## What is the impact of Spring Cloud vulnerability?
The spring
Talos
Threat Advisory: Spring4Shell
blogs_talos·2022-03-31·CVSS 6.0
CVE-2022-22965 [MEDIUM] Threat Advisory: Spring4Shell
## UPDATE, APRIL 4, 2022:
The Kenna Risk Score for CVE-2022-22965 is currently at maximum 100. This is an exceptionally rare score, of which only 415 out of 184,000 CVEs (or 0.22 percent) have achieved, reflecting the severity and potential effects of this vulnerability. To get a risk score this high means it is a widely deployed technology with a public exploit available, and we have seen proof of an ongoing active internet breach using the vulnerability.
Kenna Risk Scores are continually reevaluated and may shift over time. An outline of the current risk score is below:
Cisco Talos is releasing coverage to protect users against the exploitation of two remote code execution vulnerabilities in Spring Framework. CVE-2022-22963 is a medium-severity bug that affects Spring Cloud and CVE-20
Unit42
CVE-2022-22965: Spring Core Remote Code Execution Vulnerability Exploited In the Wild (SpringShell) (Updated)
blogs_unit42·2022-03-31·CVSS 6.0
CVE-2022-22965 [MEDIUM] CVE-2022-22965: Spring Core Remote Code Execution Vulnerability Exploited In the Wild (SpringShell) (Updated)
## Executive Summary
Recently, two vulnerabilities were announced within the Spring Framework, an open-source framework for building enterprise Java applications. On March 29, 2022, the Spring Cloud Expression Resource Access Vulnerability tracked in CVE-2022-22963 was patched with the release of Spring Cloud Function 3.1.7 and 3.2.3. Two days later on March 31, 2022, Spring released version 5.3.18 and 5.2.20 of Spring Framework to patch another more severe vulnerability tracked in CVE-2022-22965. The CVE-2022-22965 vulnerability allows an attacker unauthenticated remote code execution (RCE), which Unit 42 has observed being exploited in the wild. The exploitation of this vulnerability could result in a webshell being installed onto the compromised server that allows further command execu
Qualys
Spring Framework Zero-Day Remote Code Execution (Spring4Shell) Vulnerability
blogs_qualys·2022-03-31
Spring Framework Zero-Day Remote Code Execution (Spring4Shell) Vulnerability
## Table of Contents
What is Spring Framework?
Which versions are vulnerable?
How can this be exploited?
What are the prerequisites to exploit this vulnerability?
Is there a patch available for Spring4Shell?
Qualys Coverage
Discover Your Attack Surface with up-to-date CyberSecurity Asset Management
Detect the Vulnerability with Qualys WAS
Detect Spring4Shell Vulnerability Using Qualys VMDR
Track Spring4Shell Progress with Unified Dashboard
Detect Spring4Shell Vulnerabilities in Running Containers & Images
Remediate Spring4Shell Using Qualys Patch Management
FAQ:
Updates
A new zero-day Remote Code Execution (RCE) vulnerability, “Spring4Shell” or “SpringShell” was disclosed in the Spring framework. An unauthorized attacker can exploit this vulnerability to remotely execute arb
Talos
Threat Advisory: Spring4Shell
blogs_talos·2022-03-31·CVSS 6.0
CVE-2022-22965 [MEDIUM] Threat Advisory: Spring4Shell
## Threat Advisory: Spring4Shell
## UPDATE, APRIL 4, 2022:
The Kenna Risk Score for CVE-2022-22965 is currently at maximum 100. This is an exceptionally rare score, of which only 415 out of 184,000 CVEs (or 0.22 percent) have achieved, reflecting the severity and potential effects of this vulnerability. To get a risk score this high means it is a widely deployed technology with a public exploit available, and we have seen proof of an ongoing active internet breach using the vulnerability.
Kenna Risk Scores are continually reevaluated and may shift over time. An outline of the current risk score is below:
Cisco Talos is releasing coverage to protect users against the exploitation of two remote code execution vulnerabilities in Spring Framework. CVE-2022-22963 is a medium-severity bug th
Unit42
CVE-2022-22965: Spring Core Remote Code Execution Vulnerability Exploited In the Wild (SpringShell) (Updated)
blogs_unit42·2022-03-31·CVSS 9.8
CVE-2022-22965 [CRITICAL] CVE-2022-22965: Spring Core Remote Code Execution Vulnerability Exploited In the Wild (SpringShell) (Updated)
Threat Research Center
High Profile Threats
Vulnerabilities
## CVE-2022-22965: Spring Core Remote Code Execution Vulnerability Exploited In the Wild (SpringShell) (Updated)
Haozhe Zhang
Ken Hsu
Tao Yan
Qi Deng
Robert Falcone
Published: March 31, 2022
High Profile Threats
Vulnerabilities
CVE-2022-22963
CVE-2022-22965
Exploit in the wild
Remote Code Execution
SpringShell
## Executive Summary
Recently, two vulnerabilities were announced within the Spring Framework, an open-source framework for building enterprise Java applications. On March 29, 2022, the Spring Cloud Expression Resource Access Vulnerability tracked in CVE-2022-22963 was patched with the release of Spring Cloud Function 3.1.7 and 3.2.3. Two days later on March 31, 2022, Spring released version 5.3.18 and
Zscaler
Spring Cloud Framework Vulnerabilities | Zscaler Blog
blogs_zscaler·2022-03-31
Spring Cloud Framework Vulnerabilities | Zscaler Blog
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Qualys
Spring Framework Zero-Day Remote Code Execution (Spring4Shell) Vulnerability | Qualys
blogs_qualys·2022-03-31
Spring Framework Zero-Day Remote Code Execution (Spring4Shell) Vulnerability | Qualys
#### Table of Contents
- What is Spring Framework?
- Which versions are vulnerable?
- How can this be exploited?
- What are the prerequisites to exploit this vulnerability?
- Is there a patch available for Spring4Shell?
- Qualys Coverage
- Discover Your Attack Surface with up-to-date CyberSecurity Asset Management
- Detect the Vulnerability with Qualys WAS
- Detect Spring4Shell Vulnerability Using Qualys VMDR
- Track Spring4Shell Progress with Unified Dashboard
- Detect Spring4Shell Vulnerabilities in Running Containers & Images
- Remediate Spring4Shell Using Qualys Patch Management
- FAQ:
- Updates
A new zero-day Remote Code Execution (RCE) vulnerability, “Spring4Shell” or “SpringShell” was disclosed in the Spring framework. An unauthorized attacker can exploit this vulnerability to rem
Tenable
Spring4Shell (CVE-2022-22965) FAQ: Spring Framework Remote Code Execution Vulnerability
blogs_tenable·2022-03-30·CVSS 9.8
[CRITICAL] Spring4Shell (CVE-2022-22965) FAQ: Spring Framework Remote Code Execution Vulnerability
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Sentinelone
Log4j Zero-Day RCE (CVE-2021-44228) Vulnerability: Proof of Concept and Remediation Guidance
blogs_sentinelone·2021-09-13·CVSS 10.0
CVE-2021-44228 [CRITICAL] Log4j Zero-Day RCE (CVE-2021-44228) Vulnerability: Proof of Concept and Remediation Guidance
On the 9th of December, 2021, a new vulnerability, CVE-2021-44228, was discovered in Log4j, a popular open-source Java logging framework distributed under Apache Software License. The vulnerability is remotely exploitable without authentication, i.e., it may be exploited over a network without a username and password.
## About the RCE vulnerability
Java logging framework Log4j is used to generate logs and record the activity inside an application. The vulnerability can be exploited to allow unauthorized remote code execution on the affected servers. Hackers are still utilizing the recently discovered exploit to attack the servers. The exploit lets an attacker execute malicious Java code on the vulnerable server.
The attacker will invoke any server endpoint with a malicious payload.
The
Zscaler
ThreatLabz April 2022 Report: Conti attacks, BlackGuard sells, Spring springs a leak, and FFDroider gets social | CXO Revolutionaries
blogs_zscaler
ThreatLabz April 2022 Report: Conti attacks, BlackGuard sells, Spring springs a leak, and FFDroider gets social | CXO Revolutionaries
## ThreatLabz April 2022 Report: Conti attacks, BlackGuard sells, Spring springs a leak, and FFDroider gets social
Deepen Desai
Contributor
Zscaler
## Apr 26, 2022
Keep up with the resurrection of Conti ransomware attacks, BlackGuard, vulnerabilities in the Spring Cloud Framework, and the distribution of malware targeting social-media account credentials.
In the past month, the Zscaler ThreatLabZ security research team has documented a resurrection of Conti ransomware attacks , the arrival of a new info-stealer dubbed BlackGuard , the appearance of vulnerabilities in the Spring Cloud Framework , and the distribution of malware targeting social-media account credentials .
## Despite leak of its source code, Conti ransomware group continues attacks
In late February, a hacker released
arXiv
Red-MIRROR: Agentic LLM-based Autonomous Penetration Testing with Reflective Verification and Knowledge-augmented Interaction
arxiv_fulltext·2026-03
Red-MIRROR: Agentic LLM-based Autonomous Penetration Testing with Reflective Verification and Knowledge-augmented Interaction
1
.001
Red-MIRROR: Agentic LLM-based Autonomous Penetration Testing with Reflective Verification and Knowledge-augmented Interaction
[1]organization=Information Security Lab, University of Information Technology,
city=Ho Chi Minh City,
country=Vietnam
[2]organization=Vietnam National University,
city=Ho Chi Minh City,
country=Vietnam
[1,2]Tran Vy Khang
[email protected]
[1,2]Nguyen Dang Nguyen Khang
[email protected]
[1,2]Nghi Hoang Khoa
[email protected]
[1,2]Do Thi Thu Hien
[email protected]
[1,2]Van-Hau Pham
[email protected]
[1,2]Phan The Duycor1
[email protected]
[cor1]Corresponding author
## Abstract
Web applications remain the dominant attack surface in cybersecurity, where vulnerabilities such as SQL injection, XSS, and business logic flaws continue to cause sign
arXiv
ZTD_(JAVA): Mitigating Software Supply Chain Vulnerabilities via Zero-Trust Dependencies
arxiv_fulltext·2024-12-20
ZTD_(JAVA): Mitigating Software Supply Chain Vulnerabilities via Zero-Trust Dependencies
Mitigating Java Supply Chain Exploits with a Runtime Permission Model
: Preventing Java Supply Chain RCE Exploits via a Usable Package-level Permission Manager
: Preventing the next Log4Shell in Java with a Supply-chain Aware Permission Manager
Preventing Supply Chain Vulnerabilities in Java with a Fine-Grained Permission Manager
A Supply-Chain-Aware Sandbox Design for Supply Chain Vulnerability Defense
Enabling Component-level Sandboxing for Supply Chain Vulnerability Defense
A Component-level Sandbox Design for Runtime Supply Chain Vulnerability Defense
Enabling a for Mitigating Software Supply Chain Vulnerability Exploitation
Enabling a for Mitigating Software Supply Chain Vulnerability Exploitation in Java
: Enabling a for Mitigating Software Supply Chain Vulnerability Exploitation in
CTF
Inject / README
ctf_writeups
Inject / README
# Inject
> Write-up author: jon-brandy
## STEPS:
> PORT SCANNING
```
┌──(brandy㉿bread-yolk)-[~]
└─$ nmap -p- -sVC 10.10.11.204 --min-rate 1000
Starting Nmap 7.93 ( https://nmap.org ) at 2023-09-26 04:39 PDT
Nmap scan report for inject.htb (10.10.11.204)
Host is up (0.065s latency).
Not shown: 65533 closed tcp ports (conn-refused)
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.5 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 3072 caf10c515a596277f0a80c5c7c8ddaf8 (RSA)
| 256 d51c81c97b076b1cc1b429254b52219f (ECDSA)
|_ 256 db1d8ceb9472b0d3ed44b96c93a7f91d (ED25519)
8080/tcp open nagios-nsca Nagios NSCA
|_http-title: Home
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
Service detection performed. Please report any incorrect results at https://nmap.org/subm
CTF
Inject / README
ctf_writeups·CVSS 9.8
CVE-2022-22963 [CRITICAL] Inject / README
# Inject - HackTheBox - Writeup
Linux, 20 Base Points, Easy
## Machine
## TL;DR
To solve this machine, we start by using `nmap` to enumerate open services and find ports `22`, and `8080`.
***User***: Discovered a Local File Inclusion vulnerability on the image upload feature, which led to the discovery of a `pom.xml` file that revealed a vulnerable version of `spring-cloud-function-web` with `CVE-2022-22963`. Exploited the vulnerability to gain a reverse shell as `frank`. Found `phil`'s credentials in the `settings.xml` file on the `/home/frank/.m2/` directory.
***Root***: Observed a scheduled task running on the target machine which removed the contents of a directory `/opt/automation/tasks/` and copied the original file `playbook_1.yml` from `/root`. Found an Ansible playbook in
http://packetstormsecurity.com/files/173430/Spring-Cloud-3.2.2-Remote-Command-Execution.htmlhttps://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0005https://tanzu.vmware.com/security/cve-2022-22963https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-java-spring-scf-rce-DQrHhJxHhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttp://packetstormsecurity.com/files/173430/Spring-Cloud-3.2.2-Remote-Command-Execution.htmlhttps://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0005https://tanzu.vmware.com/security/cve-2022-22963https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-java-spring-scf-rce-DQrHhJxHhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-22963
2022-04-01
Published
2022-08-25
Added to CISA KEV
Exploited in the wild