SBN

Spring4Shell Vulnerability Sets Off Alarms

Spring4Shell Vulnerability Sets Off Alarms
brooke.crothers
Wed, 04/06/2022 – 18:30

What is the Spring Framework and Spring4Shell exploit?

The Spring Framework is an Open Source programming and configuration model providing infrastructure support for developers building Java applications (via Check Point). It is used by millions of web applications and websites and one of the most popular frameworks for the java programming language. It has become popular in the Java community as an addition to the Enterprise JavaBeans (EJB) model.

The exploit is a zero-day vulnerability in the Spring Core Java framework that may allow unauthenticated remote code execution (RCE) on vulnerable applications. It was publicly disclosed on March 30 before a patch was released.

The vulnerability is newly listed as CVE-2022-22965 by the National Vulnerability Database.

Microsoft reacts

Microsoft responded publicly with a blog on April 4, describing the threat.

“The Spring Framework is the most widely used lightweight open-source framework for Java. In Java Development Kit (JDK) version 9.0 or later, a remote attacker can obtain an AccessLogValve object through the framework’s parameter binding feature and use malicious field values to trigger the pipeline mechanism and write to a file in an arbitrary path, if certain conditions are met.

“The vulnerability in Spring Core—referred to in the security community as SpringShell or Spring4Shell—can be exploited when an attacker sends a specially crafted query to a web server running the Spring Core framework. Other vulnerabilities disclosed in the same component are less critical and not tracked as part of this blog.”

SpringShell RCE vulnerability: Guidance for protecting against and detecting CVE-2022-22965, Microsoft Security Blog, updated April 4, 2022

In the course of monitoring attacks against its cloud infrastructure and services, Microsoft said it has been tracking a low volume of exploit attempts but has not seen a significant increase in quantity of attacks or new campaigns as of April 5.

VMWare has also published security updates for Spring4Shell.

How severe is it?

A report at Ars Technica disputed the seriousness of the exploit.

“Hype and hyperbole were on full display this week as the security world reacted to reports of yet another Log4Shell,” according to the report.

And some later reports downplayed the severity, after initial breathless warnings of what could happen.

“While some have compared this security bug’s severity level with Log4Shell…this isn’t necessarily true given that Spring4Shell only impacts systems with a very particular configuration,” said BleepingComputer.

Some, including Will Dormann, Vulnerability Analyst at the CERT/CC, took a dim view of the initial overreaction to the vulnerability.  

But Dormann later revised his initial take and said it actually was a “thing.”

“And to tie up this thread, I’ve confirmed that #SpringShell / #Spring4Shell *IS* indeed a thing,” Dormann said in a tweet.

On April 1, the US Cybersecurity and Infrastructure Security Agency (CISA) urged all organizations in the U.S. to patch immediately.

Related Posts

spring4shell-exploit

Brooke Crothers

Organizations worldwide have been impacted by Spring4Shell vulnerability exploitation attempts. Microsoft, meanwhile, reported vulnerabilities in the Spring Framework for Java.  But some reports have questioned the gravity of the exploit.

Why are TLS certificates such a hot commodity on the dark web? Read the report to find out!

“>

Off
UTM Medium
Resources

UTM Source
Blog

UTM Campaign
Recommended-Resources

*** This is a Security Bloggers Network syndicated blog from Rss blog authored by brooke.crothers. Read the original post at: https://www.venafi.com/blog/spring4shell-vulnerability-sets-alarms