Podatność w VMware Spring Framework umożliwia zdalne wykonanie kodu (RCE) poprzez mechanizm data binding w aplikacjach Spring MVC lub Spring WebFlux uruchomionych na JDK 9 lub nowszym. Ze względu na ocenę CVSS 9.8 i aktywne wykorzystywanie w środowiskach produkcyjnych stanowi krytyczne zagrożenie.
▸ Pokaż oryginał (EN)
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.
Podatność wynika z nieprawidłowej obsługi data binding w Spring MVC oraz Spring WebFlux, co pozwala atakującemu na manipulację właściwościami klas Javy za pośrednictwem żądań HTTP. Szczegółowy exploit wymaga, aby aplikacja była wdrożona jako plik WAR na serwerze Apache Tomcat. Aplikacje uruchomione jako Spring Boot executable JAR (domyślny sposób wdrożenia) nie są podatne na opisany wektor ataku, jednak ogólna natura podatności sugeruje możliwość istnienia innych wektorów eksploatacji.
Nieuwierzytelniony, zdalny atakujący może uzyskać pełną kontrolę nad serwerem poprzez zdalne wykonanie dowolnego kodu (RCE), co prowadzi do naruszenia poufności, integralności oraz dostępności systemu.
Należy zastosować patche dostępne u producenta zgodnie z referencjami (m.in. https://tanzu.vmware.com/security/cve-2022-22965). Jako obejście należy rozważyć migrację wdrożeń WAR na Tomcat do modelu Spring Boot executable JAR. Zalecana jest również weryfikacja konfiguracji data binding i ograniczenie dozwolonych właściwości przez globalne ustawienia @InitBinder.
VMware Spring Framework działający na JDK 9 lub nowszym, wdrożony jako aplikacja WAR na serwerze Tomcat; dotyczy również Oracle JDK, Cisco CX Cloud Agent oraz Oracle Communications Cloud Native Core Automated Test Suite — dokładne wersje wskazane w referencjach producenta
Podatność znana publicznie pod nazwą 'Spring4Shell'. Publiczne exploity dostępne w serwisie Packet Storm Security (referencje w opisie). CISA potwierdziła aktywne wykorzystywanie w środowiskach produkcyjnych.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCisco Cx Cloud Agent
APPCisco< 2.1.0Oracle Commerce Platform
APPOracle11.3.2Oracle Communications Cloud Native Core Automated Test Suite
APPOracle1.9.022.1.0Oracle Communications Cloud Native Core Binding Support Function
APPOracle22.1.3Oracle Communications Cloud Native Core Console
APPOracle1.9.022.1.0Oracle Communications Cloud Native Core Network Exposure Function
APPOracle22.1.0Oracle Communications Cloud Native Core Network Function Cloud Native Environment
APPOracle1.10.022.1.0Oracle Communications Cloud Native Core Network Repository Function
APPOracle1.15.022.1.0Oracle Communications Cloud Native Core Network Slice Selection Function
APPOracle1.15.01.8.022.1.0Oracle Communications Cloud Native Core Policy
APPOracle1.15.022.1.0Oracle Communications Cloud Native Core Security Edge Protection Proxy
APPOracle1.7.022.1.0Oracle Communications Cloud Native Core Unified Data Repository
APPOracle1.15.022.1.0Oracle Communications Policy Management
APPOracle12.6.0.0.0Oracle Communications Unified Inventory Management
APPOracle7.4.17.4.27.5.0Oracle Financial Services Analytical Applications Infrastructure
APPOracle8.1.18.1.2.0Oracle Financial Services Behavior Detection Platform
APPOracle8.1.1.08.1.1.18.1.2.0Oracle Financial Services Enterprise Case Management
APPOracle8.1.1.08.1.1.18.1.2.0Oracle JDK
APPOracle≥ 9Oracle MySQL Enterprise Monitor
APPOracle< 8.0.29Oracle Product Lifecycle Analytics
APPOracle3.6.1Oracle Retail Bulk Data Integration
APPOracle16.0.3Oracle Retail Customer Management And Segmentation Foundation
APPOracle17.018.019.0Oracle Retail Financial Integration
APPOracle14.1.3.215.0.3.116.0.319.0.1Oracle Retail Integration Bus
APPOracle14.1.3.215.0.3.116.0.319.0.1Oracle Retail Merchandising System
APPOracle16.0.319.0.1Oracle Retail Xstore Point Of Service
APPOracle20.0.121.0.0Oracle Sd Wan Edge
APPOracle9.09.1Oracle Weblogic Server
APPOracle12.2.1.3.012.2.1.4.014.1.1.0.0Siemens Operation Scheduler
APPSiemens< 2.0.4Siemens Simatic Speech Assistant For Machines
APPSiemens< 1.2.1
CISA KEV — szczegółyi
- Dostawcai
- VMware ↗
- Produkti
- Spring Framework
- Data dodania do KEVi
- 4 kwietnia 2022
- Termin remediation (USA)i
- 25 kwietnia 2022(po terminie)
Zastosuj aktualizacje zgodnie z instrukcjami producenta.
▸ Pokaż oryginał (EN)
Apply updates per vendor instructions.
Aplikacja Spring MVC lub Spring WebFlux uruchomiona na JDK 9+ może być podatna na remote code execution (RCE) poprzez data binding.
▸ Pokaż oryginał (EN)
Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.
Powiązane podatności
RCE w Spring Cloud Function poprzez złośliwy SpEL routing-expression
RCE poprzez code injection w VMware Spring Cloud Gateway (Actuator endpoint)
Apache Log4j: niekompletna naprawa CVE-2021-44228 — RCE przez JNDI Lookup
Apache Log4j2 Log4Shell — RCE przez podatną funkcję JNDI lookup
RCE w Apache Struts 2 poprzez wymuszoną ewaluację OGNL