March 31, 2022 at 12:44 PM
Spring4Shell RCE (CVE-2022-22963)
Spring4Shell: Security Analysis of the latest Java RCE '0-day' vulnerabilities in Spring
On March 29th, 2022, two RCE vulnerabilities were being discussed on the internet. Most of the people talking about them believe they're talking about "Spring4Shell", but in reality they're swapping notes about CVE-2022-22963.
https://www.lunasec.io/docs/blog/spring-rce-vulnerabilities/
POCs (any leecher hide):
More:
https://www.cyberkendra.com/2022/03/rce-0-day-exploit-found-in-spring-cloud.html
https://nsfocusglobal.com/spring-cloud-function-spel-expression-injection-vulnerability-alert/
Spring4Shell: Security Analysis of the latest Java RCE '0-day' vulnerabilities in Spring
On March 29th, 2022, two RCE vulnerabilities were being discussed on the internet. Most of the people talking about them believe they're talking about "Spring4Shell", but in reality they're swapping notes about CVE-2022-22963.
https://www.lunasec.io/docs/blog/spring-rce-vulnerabilities/
POCs (any leecher hide):
More:
https://www.cyberkendra.com/2022/03/rce-0-day-exploit-found-in-spring-cloud.html
https://nsfocusglobal.com/spring-cloud-function-spel-expression-injection-vulnerability-alert/
My kung fu is stronger than yours...

