Spring Framework vulnerability CVE-2022-22965 (Spring4shell)
?? Saral Saxena ??????
?11K+ Followers | Linkedin Top Voice || Associate Director || 15+ Years in Java, Microservices, Kafka, Spring Boot, Cloud Technologies (AWS, GCP) | Agile , K8s ,DevOps & CI/CD Expert
On March 31, 2022, a fatal vulnerability was confirmed in Spring Framework, and a fixed version was released.?Here is a summary of related information.
1. 1.?What happened?
2. 2.?What happens when a vulnerability is exploited?
3. 3.?What are the affected conditions?
If all of the following conditions are met, it may be affected by the vulnerability.
These conditions are as of March 31, 2022.?Please refer to the official latest information as new methods of exploiting vulnerabilities may be confirmed in future verifications and evaluations.
Affected version
Environment to pay particular attention to
If any of the following applies to the environment that meets the conditions, it is possible that you have already been attacked, and we strongly recommend that you take measures that include effects other than patch application (whether or not there is infringement, etc.).
领英推荐
4.?How should I deal with the vulnerability?
Since it is a highly urgent vulnerability, it is recommended to take measures to mitigate the impact of the attack in parallel (or priority) with detailed understanding.
Correspondence ① Update to the latest version
Countermeasure (2) Applying workarounds
5.?Has it been abused already?