Home / Companies / Sysdig / Blog / Post Details
Content Deep Dive

Critical Vulnerability in Spring Core: CVE-2022-22965 a.k.a. Spring4Shell

Blog post from Sysdig

Post Details
Company
Date Published
Author
Stefano Chierici
Word Count
1,003
Company Posts That Month
13
Language
English
Hacker News Points
-
Post removed?
No
Summary

A critical vulnerability known as Spring4Shell (CVE-2022-22965) has been identified in the popular Java framework Spring Core on JDK9+, which allows remote code execution (RCE) by exploiting class injection vulnerabilities, potentially leading to a complete system compromise. This vulnerability affects versions 5.3.0 to 5.3.17 and 5.2.0 to 5.2.19, including older unsupported versions, and requires certain conditions to be met, such as using JDK 9 or higher, Apache Tomcat, and specific dependencies. The vulnerability is distinct from CVE-2022-22963, which impacts Spring Cloud. To mitigate the risk, affected systems should be updated to versions 5.3.18+ or 5.2.20+, and detection can be achieved using tools like Sysdig for scanning during the build, deployment, and runtime phases. The article emphasizes the importance of continuous monitoring and adapting security policies to address emerging threats in real-time.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Serverless 2 585 126 56 -21%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.